| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wmj8-9953-vff5 | OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opencost
Opencost opencost |
|
| Vendors & Products |
Opencost
Opencost opencost |
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is written to the GCP service-account key.json file returned by GetGCPAuthSecretFilePath in core/pkg/env/core.go. The attacker controls the file contents but not the CONFIG_PATH-derived directory, the key.json filename, or the file mode. Replacing the credential contents can disrupt GCP cost collection or cause OpenCost to use attacker-selected credentials, and the wildcard Access-Control-Allow-Origin response permits browser-assisted requests when the service is reachable from a browser. This issue is fixed in version 1.121.0. | |
| Title | OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection | |
| Weaknesses | CWE-20 CWE-309 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T19:45:01.536Z
Reserved: 2026-05-05T17:39:31.113Z
Link: CVE-2026-44300
Updated: 2026-09-15T19:16:36.678Z
Status : Received
Published: 2026-09-15T18:17:21.280
Modified: 2026-09-15T20:17:15.993
Link: CVE-2026-44300
No data.
OpenCVE Enrichment
Updated: 2026-09-15T19:30:11Z
Github GHSA