Affected by GO-2026-4515
and 2 other vulnerabilities
GO-2026-4515: Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints in github.com/akuity/kargo
GO-2026-4516: Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints in github.com/akuity/kargo
GO-2026-4717: Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration in github.com/akuity/kargo
GetEnvInt retrieves the value of an environment variable having the specified
key. If the value is empty string, or cannot parse as an int, a specified
default is returned instead.