Skip to content

Private helm repository credentials leak

Critical
olevitt published GHSA-m773-6vm8-8x6q Sep 4, 2025

Package

onyxia-api (onyxia-api)

Affected versions

< 4.9.0

Patched versions

4.9.0

Description

Impact

Up to version 4.9.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.
Only instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected.
This optional feature was added in Onyxia-API v4.6.0 (Onyxia 10.18.0, May 21th 2025).

Patches

Issue has been fixed in version 4.9.0 of Onyxia-API (Onyxia 10.28)

Workarounds

Users that can't upgrade to API 4.9.0 (minor upgrade from 4.6.0) are advised to remove any private helm repositories from their catalogs configuration to prevent the credentials from leaking.

Severity

Critical

CVE ID

CVE-2025-58366

Weaknesses

No CWEs

Credits