—
GO-2026-6517
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
Quick fix
GO-2026-6517 — github.com/kcp-dev/kcp: upgrade to the fixed version with the command below.
go get github.com/kcp-dev/kcp@v0.31.4Details
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
Are you affected?
Enter the version of the package you're using.