github.com/akuity/kargo
Application lifecycle orchestration
Activity
- Latest release
- 1w ago
- Total releases
- 67
- Cadence
- ~7 days
- Last 12 months
- 35
Reach
- Stars
- 3.6k
Details
- First release
- Mar 31, 2023
| Version | Released | |
|---|---|---|
v1.11.4
patch
|
v1.11.4
patch
Dependencies (84)
+ 76 more |
|
v1.10.12
patch
|
v1.10.12
patch
Dependencies (85)
+ 77 more |
|
v1.10.11
patch
|
v1.10.11
patch
Dependencies (85)
+ 77 more |
|
v1.11.3
patch
|
v1.11.3
patch
Dependencies (84)
+ 76 more |
|
v1.11.2
patch
|
v1.11.2
patch
Dependencies (84)
+ 76 more |
|
v1.10.10
patch
|
v1.10.10
patch
Dependencies (85)
+ 77 more |
|
v1.11.1
patch
|
v1.11.1
patch
Dependencies (84)
+ 76 more |
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (84)
+ 76 more |
|
v1.11.0-rc.6
pre
|
v1.11.0-rc.6
pre
Dependencies (84)
+ 76 more |
|
v1.11.0-rc.5
pre
|
v1.11.0-rc.5
pre
Dependencies (84)
+ 76 more |
|
v1.11.0-rc.4
pre
|
v1.11.0-rc.4
pre
Dependencies (86)
+ 78 more |
|
v1.11.0-rc.3
pre
|
v1.11.0-rc.3
pre
Dependencies (86)
+ 78 more |
|
v1.10.9
patch
|
v1.10.9
patch
Dependencies (85)
+ 77 more |
|
v1.11.0-rc.2
pre
|
v1.11.0-rc.2
pre
Dependencies (86)
+ 78 more |
|
v1.11.0-rc.1
pre
|
v1.11.0-rc.1
pre
Dependencies (86)
+ 78 more |
|
v1.10.8
patch
|
v1.10.8
patch
Dependencies (85)
+ 77 more |
|
v1.10.7
patch
|
v1.10.7
patch
Dependencies (85)
+ 77 more |
|
v1.10.6
patch
|
v1.10.6
patch
Dependencies (85)
+ 77 more |
|
v1.10.5
patch
|
v1.10.5
patch
Dependencies (85)
+ 77 more |
|
v1.10.4
patch
|
v1.10.4
patch
Dependencies (86)
+ 78 more |
|
v1.10.3
patch
|
v1.10.3
patch
Dependencies (83)
+ 75 more |
|
v1.10.2
patch
|
v1.10.2
patch
Dependencies (83)
+ 75 more |
|
v1.7.10
patch
|
v1.7.10
patch
Dependencies (77)
+ 69 more |
|
v1.10.1
minor
1 CVE
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
v1.10.1
minor
Dependencies (83)
+ 75 more |
|
v1.10.0
minor
1 CVE
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
v1.10.0
minor
Dependencies (83)
+ 75 more |
|
v1.10.0-rc.8
pre
|
v1.10.0-rc.8
pre
Dependencies (83)
+ 75 more |
|
v1.10.0-rc.7
pre
|
v1.10.0-rc.7
pre
Dependencies (83)
+ 75 more |
|
v1.10.0-rc.6
pre
|
v1.10.0-rc.6
pre
Dependencies (83)
+ 75 more |
|
v1.10.0-rc.5
pre
|
v1.10.0-rc.5
pre
Dependencies (83)
+ 75 more |
|
v1.9.5
patch
1 CVE
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev |
v1.9.5
patch
Dependencies (84)
+ 76 more |
|
v1.9.2
minor
4 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27111
GO-2026-4515
GHSA-5vvm-67pj-72g4
Feb 23, 2026
Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints in github.com/akuity/kargo Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints in github.com/akuity/kargo Fixed in
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev |
v1.9.2
minor
Dependencies (84)
+ 76 more |
|
v1.7.7
patch
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev |
v1.7.7
patch
Dependencies (77)
+ 69 more |
|
v1.8.4
patch
4 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (78)
+ 70 more |
|
v1.8.1
minor
4 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (78)
+ 70 more |
|
v1.7.6
patch
4 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.6
patch
Dependencies (77)
+ 69 more |
|
v1.7.4
minor
4 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-27112
GO-2026-4516
GHSA-7g9x-cp9g-92mr
Feb 23, 2026
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo Fixed in
1.7.8
1.8.11
1.9.3
References Updated Feb 23, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.4
minor
Dependencies (77)
+ 69 more |
|
v1.7.0-rc.2
pre
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.7.0-rc.2
pre
Dependencies (77)
+ 69 more |
|
v1.6.2
minor
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.2
minor
Dependencies (76)
+ 68 more |
|
v1.6.0-rc.4
pre
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.0-rc.4
pre
Dependencies (76)
+ 68 more |
|
v1.6.0-rc.3
pre
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.6.0-rc.3
pre
Dependencies (76)
+ 68 more |
|
v1.5.3
minor
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.3
minor
Dependencies (74)
+ 66 more |
|
v1.5.0-rc.4
pre
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.0-rc.4
pre
Dependencies (74)
+ 66 more |
|
v1.5.0-rc.1
pre
3 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-32828
GO-2026-4717
GHSA-j94x-8wcp-x7hm
Mar 26, 2026
Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo Fixed in
1.6.4
1.7.9
1.8.12
1.9.5
References Updated Mar 26, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.5.0-rc.1
pre
Dependencies (74)
+ 66 more |
|
v1.2.0-rc.1
pre
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (68)
+ 60 more |
|
v1.1.2-rc.2
pre
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2-rc.2
pre
Dependencies (66)
+ 58 more |
|
v1.1.2-rc.1
pre
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.2-rc.1
pre
Dependencies (68)
+ 60 more |
|
v1.1.0
minor
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (66)
+ 58 more |
|
v1.1.0-rc.2
pre
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0-rc.2
pre
Dependencies (66)
+ 58 more |
|
v1.0.1
major
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (64)
+ 56 more |
|
v1.0.0-rc.4
pre
2 CVEs
CVE-2026-42350
GO-2026-6301
GHSA-g7gw-m874-7rmf
Aug 27, 2026
Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter in github.com/akuity/kargo Fixed in
1.7.10
1.8.13
1.9.8
1.10.2
References
Updated Aug 27, 2026 · Source: OSV.dev
CVE-2026-24748
GO-2026-4385
GHSA-w5wv-wvrp-v5m5
Feb 02, 2026
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo Kargo's Fixed in
1.6.3
1.7.7
1.8.7
References
Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (64)
+ 56 more |