Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3j3q-wp9x-585p | kcp's cache server is accessible without authentication or authorization checks |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 10 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kcp-dev
Kcp-dev kcp |
|
| Vendors & Products |
Kcp-dev
Kcp-dev kcp |
Wed, 08 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.30.3 and 0.29.3, the cache server is directly exposed by the root shard and has no authentication or authorization in place. This allows anyone who can access the root shard to read and write to the cache server. This vulnerability is fixed in 0.30.3 and 0.29.3. | |
| Title | kcp's cache server is accessible without authentication or authorization checks | |
| Weaknesses | CWE-302 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-10T20:49:31.041Z
Reserved: 2026-04-07T00:23:30.596Z
Link: CVE-2026-39429
Updated: 2026-04-10T20:49:27.033Z
Status : Awaiting Analysis
Published: 2026-04-08T21:16:59.313
Modified: 2026-04-08T21:26:13.410
Link: CVE-2026-39429
No data.
OpenCVE Enrichment
Updated: 2026-04-09T08:27:23Z
Github GHSA