Description
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests through the API endpoints. The vulnerability exists in the isSensitiveSpec function which calls grpcomni.CreateResource without checking if the resource's metadata field is nil. When a resource is created with an empty Metadata field, the CreateResource function attempts to access resource.Metadata.Version causing a segmentation fault. This vulnerability is fixed in 1.1.5 and 1.0.2.
Published: 2025-10-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4p3p-cr38-v5xp Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
History

Thu, 04 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:siderolabs:omni:*:*:*:*:*:kubernetes:*:*

Mon, 20 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Siderolabs
Siderolabs omni
Vendors & Products Siderolabs
Siderolabs omni

Tue, 14 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Oct 2025 21:00:00 +0000

Type Values Removed Values Added
Description Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests through the API endpoints. The vulnerability exists in the isSensitiveSpec function which calls grpcomni.CreateResource without checking if the resource's metadata field is nil. When a resource is created with an empty Metadata field, the CreateResource function attempts to access resource.Metadata.Version causing a segmentation fault. This vulnerability is fixed in 1.1.5 and 1.0.2.
Title Omni is Vulnerable to DoS via Empty Create/Update Resource Requests
Weaknesses CWE-476
CWE-703
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-10-14T14:28:17.108Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59836

cve-icon Vulnrichment

Updated: 2025-10-14T14:28:13.138Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-13T21:15:34.457

Modified: 2025-12-04T21:33:52.730

Link: CVE-2025-59836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-20T16:13:20Z

Weaknesses