Affected by GO-2024-3325
and 4 other vulnerabilities
GO-2024-3325: kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
GO-2025-3538: kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
GO-2025-3985: kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
GO-2026-5088: kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
GO-2026-6517: kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
NewUnsafeNonLookupServiceAccountAuthenticator creates an service account authenticator that is not looking up
service accounts and is hence unsafe for real authentication. But the returned authentication response
can be used for non-critical purposes.