Database/Control plane, storage & DevOps
SkyPilot (sky/users/server.py, user ID derivation from username): User IDs are derived with a weak hash of the
Impact
User IDs are derived with a weak hash of the username, so a remote attacker can work toward a collision and get a user ID that belongs to someone else. Practical exploitation is difficult, but the failure mode is identity confusion in the layer that decides whose clusters and quota a request touches.
Who can reach it
Remote, unauthenticated, but high attack complexity. Affects SkyPilot up to 0.12.0. The exploit has been published.
What to do
Upgrade SkyPilot past 0.12.0 once the maintainers ship the fix tracked in issue 9194, and restart the API server. This is a VulDB-sourced report - confirm against the SkyPilot release notes before scheduling a maintenance window on it alone.
References
Related entries
- GitLab: unauthenticated GraphQL requests can read CI/CD job traces containing secret variable valuesCVE-2026-4523 · GitLab CE/EE (GraphQL API, CI/CD job traces)Low
- NATS server (TLS ciphersuite selection via CLI flags): A configuration footgun in the cluster message bus: NATSNCVD-2021-017-nats-server-tls-ciphersuite-sele · NATS server (TLS ciphersuite selection via CLI flags)Low
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM determines whether data exists on aCVE-2020-8588 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- NetApp Clustered Data ONTAP Storage Virtual Machine boundary: A user in one SVM enumerates the names of other SVMs andCVE-2020-8589 · NetApp Clustered Data ONTAP Storage Virtual Machine boundaryLow
- FlyteAdmin (list endpoints, SQL injection through list filters): FlyteAdmin's list endpoints interpolate filterCVE-2023-41891 · FlyteAdmin (list endpoints, SQL injection through list filters)Low
- GitLab EE: reporter-role author of a merge request can reset its approval rulesCVE-2026-7487 · GitLab EE (merge request approval rules, authorization check)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.