VYPR

opencost

by Opencost

Source repositories

CVEs (2)

  • CVE-2026-44300HigSep 15, 2026
    risk 0.50cvss epss 0.00

    OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoint in pkg/costmodel/router.go allows a network client to invoke AddServiceKey without mandatory authentication and submit an arbitrary key form value that is…

  • CVE-2026-67349HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers…