Vulnerability Report: GO-2026-6105
- GHSA-c534-2w9c-x7fm
- Affects: github.com/zxh326/kite
- Published: Aug 18, 2026
- Unreviewed
Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources in github.com/zxh326/kite
For detailed information about this vulnerability, visit https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm.
Affected Modules
-
PathGo Versions
-
from v0.6.9 before v0.14.1
Aliases
References
- https://github.com/kite-org/kite/security/advisories/GHSA-c534-2w9c-x7fm
- https://github.com/kite-org/kite/commit/08116eed557f8d6982cc83af0b02991e0f3577d5
- https://github.com/kite-org/kite/commit/69ad938937af8f375a2e183d1a331926ab851d98
- https://github.com/kite-org/kite/pull/638
- https://github.com/kite-org/kite/releases/tag/v0.14.1
- https://vuln.go.dev/ID/GO-2026-6105.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.