Security: akuity/kargo
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data ExfiltrationGHSA-j94x-8wcp-x7hm published
Mar 14, 2026 by krancourModerate -
Authorization Bypass Vulnerability in Batch Resource Creation API EndpointsGHSA-7g9x-cp9g-92mr published
Feb 17, 2026 by krancourCritical -
Missing Authorization Vulnerabilities in Approval & Promotion REST API EndpointsGHSA-5vvm-67pj-72g4 published
Feb 17, 2026 by krancourModerate -
`GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated accessGHSA-w5wv-wvrp-v5m5 published
Jan 27, 2026 by thomastaylor312Moderate -
Open Redirect in UI OIDC Login Flow via redirectTo Query ParameterGHSA-g7gw-m874-7rmf published
Apr 22, 2026 by krancourLow
Learn more about advisories related to akuity/kargo in the GitHub Advisory Database