Use of Password System for Primary Authentication Affecting github.com/opencost/opencost/pkg/costmodel package, versions <1.120


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.75% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMOPENCOSTOPENCOSTPKGCOSTMODEL-17972556
  • published14 Jul 2026
  • disclosed14 Jul 2026
  • creditUnknown

Introduced: 14 Jul 2026

CVE-2026-44300  (opens in a new tab)
CWE-309  (opens in a new tab)

How to fix?

Upgrade github.com/opencost/opencost/pkg/costmodel to version 1.120 or higher.

Overview

Affected versions of this package are vulnerable to Use of Password System for Primary Authentication via the AddServiceKey function. An attacker can overwrite sensitive credential files and inject malicious content by sending unauthenticated POST requests to the /serviceKey endpoint, which accepts user-supplied data without validation or authentication. This can result in service disruption, unauthorized access to cloud resources, and potential data leakage. This is only exploitable if the service is accessible over the network without additional access controls or authentication mechanisms.

Workaround

This vulnerability can be mitigated by restricting network access to the service using NetworkPolicies, disabling the /serviceKey endpoint if not required, monitoring changes to the credential file, or mounting the configuration directory as read-only.

CVSS Base Scores

version 4.0
version 3.1