—
GO-2025-4021
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni
Quick fix
GO-2025-4021 — github.com/siderolabs/omni: upgrade to the fixed version with the command below.
go get github.com/siderolabs/omni@v1.0.2Details
Omni is Vulnerable to DoS via Empty Create/Update Resource Requests in github.com/siderolabs/omni
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/siderolabs/omni
Introduced in:
0Fixed in: 1.0.2Fix
go get github.com/siderolabs/omni@v1.0.2References
- https://github.com/siderolabs/omni/security/advisories/GHSA-4p3p-cr38-v5xp[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-59836[ADVISORY]
- https://github.com/siderolabs/omni/commit/1396083f766a1b0380e9949968d7fc17b7afecaa[FIX]
- https://github.com/siderolabs/omni/commit/1fd954af64985a8b3dbf5b11deddbf7cd953f5ae[FIX]