—
GO-2026-6229
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Quick fix
GO-2026-6229 — github.com/kubev2v/migration-planner: upgrade to the fixed version with the command below.
go get github.com/kubev2v/migration-planner@v0.13.5Details
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs in github.com/kubev2v/migration-planner
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/kubev2v/migration-planner
Introduced in:
0Fixed in: 0.13.5Fix
go get github.com/kubev2v/migration-planner@v0.13.5References
- https://github.com/advisories/GHSA-v5m8-5455-qw2x[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-53470[ADVISORY]
- https://github.com/kubev2v/migration-planner/commit/ec47a336a620f4a995f29c1c53e4e4bd70a26e00[FIX]
- https://github.com/kubev2v/migration-planner/pull/1218[FIX]
- https://access.redhat.com/security/cve/CVE-2026-53470[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2487069[WEB]