Affected by GO-2024-3325
and 4 other vulnerabilities
GO-2024-3325: kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
GO-2025-3538: kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
GO-2025-3985: kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
GO-2026-5088: kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
GO-2026-6517: kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
WithOptionalAuthentication creates a handler that authenticates a request
if a ClientCert is presented but passes through to the next handler if one is
not.
When additionalAuthMethods is true we also attempt to authenticate even when
no client cert is detected in the request.