GO-2026-5102
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma
Quick fix
GO-2026-5102 — github.com/kumahq/kuma/v2: upgrade to the fixed version with the command below.
go get github.com/kumahq/kuma/v2@v2.7.25 Details
Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin in github.com/kumahq/kuma.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/kumahq/kuma/v2 from v2.9.0 before v2.9.15.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 No fixed version published yet for github.com/kumahq/kuma (go modules). Pin to a known-safe version or switch to an alternative.
0 Fixed in: 2.7.25 go get github.com/kumahq/kuma/v2@v2.7.25 References
- https://github.com/kumahq/kuma/security/advisories/GHSA-3vcp-chfh-f6r2 [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-45021 [ADVISORY]
- https://github.com/kumahq/kuma/commit/8fefa8595d44eb68d922405702ed7a0826322907 [FIX]
- https://github.com/kumahq/kuma/pull/16416 [FIX]
- https://github.com/kumahq/kuma/pull/16423 [FIX]
- https://github.com/kumahq/kuma/pull/16424 [FIX]
- https://github.com/kumahq/kuma/pull/16425 [FIX]
- https://github.com/kumahq/kuma/pull/16426 [FIX]
- https://github.com/kumahq/kuma/pull/16427 [FIX]