github.com/siderolabs/omni
SaaS-simple deployment of Kubernetes - on your own hardware.
Activity
- Latest release
- 3d ago
- Total releases
- 77
- Cadence
- ~6 days
- Last 12 months
- 42
Reach
- Stars
- 1.4k
Details
- First release
- Mar 07, 2024
| Version | Released | |
|---|---|---|
v1.12.0
minor
|
v1.12.0
minor
Dependencies (103)
+ 95 more |
|
v1.12.0-beta.0
pre
|
v1.12.0-beta.0
pre
Dependencies (103)
+ 95 more |
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (103)
+ 95 more |
|
v1.10.6
patch
|
v1.10.6
patch
Dependencies (102)
+ 94 more |
|
v1.11.0-beta.1
pre
|
v1.11.0-beta.1
pre
Dependencies (103)
+ 95 more |
|
v1.11.0-beta.0
pre
|
v1.11.0-beta.0
pre
Dependencies (103)
+ 95 more |
|
v1.10.5
patch
|
v1.10.5
patch
Dependencies (102)
+ 94 more |
|
v1.10.4
patch
|
v1.10.4
patch
Dependencies (102)
+ 94 more |
|
v1.10.3
patch
|
v1.10.3
patch
Dependencies (102)
+ 94 more |
|
v1.10.2
patch
|
v1.10.2
patch
Dependencies (102)
+ 94 more |
|
v1.10.1
patch
|
v1.10.1
patch
Dependencies (102)
+ 94 more |
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (102)
+ 94 more |
|
v1.10.0-beta.0
pre
|
v1.10.0-beta.0
pre
Dependencies (102)
+ 94 more |
|
v1.9.3
patch
|
v1.9.3
patch
Dependencies (101)
+ 93 more |
|
v1.9.2
minor
|
v1.9.2
minor
Dependencies (101)
+ 93 more |
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (101)
+ 93 more |
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (101)
+ 93 more |
|
v1.9.0-beta.1
pre
|
v1.9.0-beta.1
pre
Dependencies (101)
+ 93 more |
|
v1.9.0-beta.0
pre
|
v1.9.0-beta.0
pre
Dependencies (101)
+ 93 more |
|
v1.8.2
patch
|
v1.8.2
patch
Dependencies (99)
+ 91 more |
|
v1.8.1
minor
|
v1.8.1
minor
Dependencies (99)
+ 91 more |
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (99)
+ 91 more |
|
v1.8.0-beta.1
pre
|
v1.8.0-beta.1
pre
Dependencies (99)
+ 91 more |
|
v1.8.0-beta.0
pre
|
v1.8.0-beta.0
pre
Dependencies (99)
+ 91 more |
|
v1.6.6
patch
|
v1.6.6
patch
Dependencies (96)
+ 88 more |
|
v1.7.3
patch
|
v1.7.3
patch
Dependencies (99)
+ 91 more |
|
v1.7.2
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (99)
+ 91 more |
|
v1.7.1
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (99)
+ 91 more |
|
v1.7.0
minor
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (99)
+ 91 more |
|
v1.7.0-beta.1
pre
|
v1.7.0-beta.1
pre
Dependencies (99)
+ 91 more |
|
v1.7.0-beta.0
pre
|
v1.7.0-beta.0
pre
Dependencies (99)
+ 91 more |
|
v1.6.2
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (96)
+ 88 more |
|
v1.6.1
minor
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (96)
+ 88 more |
|
v1.5.7
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.5.7
patch
Dependencies (97)
+ 89 more |
|
v1.5.3
minor
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.5.3
minor
Dependencies (97)
+ 89 more |
|
v1.4.8
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.8
patch
Dependencies (101)
+ 93 more |
|
v1.5.0-beta.2
pre
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.5.0-beta.2
pre
Dependencies (98)
+ 90 more |
|
v1.4.7
patch
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.7
patch
Dependencies (101)
+ 93 more |
|
v1.4.0
minor
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (101)
+ 93 more |
|
v1.4.0-beta.0
pre
3 CVEs
CVE-2026-45726
GO-2026-5725
GHSA-wv8c-6mx2-xf4j
Jun 25, 2026
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.0-beta.0
pre
Dependencies (101)
+ 93 more |
|
v1.3.0-beta.2
pre
2 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.0-beta.2
pre
Dependencies (99)
+ 91 more |
|
v1.3.0-beta.1
pre
2 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.0-beta.1
pre
Dependencies (99)
+ 91 more |
|
v1.2.0
minor
2 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (100)
+ 92 more |
|
v1.2.0-beta.1
pre
2 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.0-beta.1
pre
Dependencies (101)
+ 93 more |
|
v1.1.4
patch
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (99)
+ 91 more |
|
v1.1.0
minor
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (99)
+ 91 more |
|
v1.0.1
major
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (99)
+ 91 more |
|
v0.51.0
minor
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.51.0
minor
Dependencies (102)
+ 94 more |
|
v0.51.0-beta.0
pre
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.51.0-beta.0
pre
Dependencies (102)
+ 94 more |
|
v0.49.1
minor
4 CVEs
CVE-2026-45723
GO-2026-5316
GHSA-c66c-vq6w-fvh5
Jun 25, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic in github.com/siderolabs/omni Omni: Operator can traverse image-factory API paths via unsanitized Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45720
GO-2026-5160
GHSA-5x9f-6vg5-qg4m
Jun 25, 2026
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token in github.com/siderolabs/omni Fixed in
1.6.6
1.7.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-59836
GO-2025-4021
GHSA-4p3p-cr38-v5xp
Nov 05, 2025
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-61688
GO-2025-4022
GHSA-77r9-w39m-9xh5
Nov 05, 2025
Omni vulnerable to information leak via API in github.com/siderolabs/omni Omni vulnerable to information leak via API in github.com/siderolabs/omni Fixed in
1.0.2
1.1.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.49.1
minor
Dependencies (100)
+ 92 more |