-
Notifications
You must be signed in to change notification settings - Fork 421
Security: kcp-dev/kcp
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual WorkspaceGHSA-q6hv-wcjr-wp8h published
Sep 26, 2025 by embikLow -
Unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual WorkspaceGHSA-w2rr-38wv-8rrp published
Mar 20, 2025 by embikCritical -
Impersonation allows access to global administrative groupsGHSA-c7xh-gjv4-4jgv published
Dec 11, 2024 by embikModerate