FlawAtlas
Search the atlas
CVE-2025-61688 High

Omni vulnerable to information leak via API in github.com/siderolabs/omni

Omni vulnerable to information leak via API in github.com/siderolabs/omni

Exploit probability 0.3%
Published November 5, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

40 explicit affected versions

Go github.com/siderolabs/omni
Go github.com/siderolabs/omni

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-61688

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.

View original source
Open Source Vulnerabilities GO-2025-4022

Omni vulnerable to information leak via API in github.com/siderolabs/omni

View original source
Open Source Vulnerabilities GHSA-77r9-w39m-9xh5

### Impact Omni might leak sensitive information via an API. ### Patches v1.1.5, v1.0.2 and v1.2.0 contain the patch. ### Workarounds None. ### References None.

View original source

05 / REFERENCES

Further evidence