PT-2025-41805 · Omni · Omni

·

CVE-2025-59836

·

Published

2025-10-13

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Omni versions prior to 1.1.5 Omni version 1.0.2
Description Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. A nil pointer dereference in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests through the API endpoints. The issue exists in the isSensitiveSpec function which calls grpcomni.CreateResource without checking if the resource's metadata field is nil. When a resource is created with an empty Metadata field, the CreateResource function attempts to access resource.Metadata.Version causing a segmentation fault.
Recommendations Update Omni to version 1.1.5 or later. Update Omni to version 1.0.2.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59836
GHSA-4P3P-CR38-V5XP
GO-2025-4021
OPENSUSE-SU-2025:15710-1
OPENSUSE-SU-2026:21483-1

Affected Products

Omni