CVE-2025-59836Medium· 5.3▾ SunlitOmni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and deni…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service by sending empty create/update resource requests through the API endpoints. The vulnerability exists in the isSensitiveSpec function which calls grpcomni.CreateResource without checking if the resource's metadata field is nil. When a resource is created with an empty Metadata field, the CreateResource function attempts to access resource.Metadata.Version causing a segmentation fault. This vulnerability is fixed in 1.1.5 and 1.0.2.
omni < 1.0.2omni >= 1.1.0, < 1.1.5Upgrade past the affected range:
omni 1.1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61688High· 8.6Omni manages Kubernetes on bare metal, virtual machines, or in a cloud
CVE-2026-45720High· 7.0Omni manages Kubernetes on bare metal, virtual machines, or in a cloud
CVE-2026-45723Low· 2.7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud
CVE-2026-45726High· 7.6Omni manages Kubernetes on bare metal, virtual machines, or in a cloud
CVE-2025-11550Medium· 6.5A vulnerability was found in Tenda W12 3.0.0.6(3948)
CVE-2021-3739High· 7.1A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’