CVE-2025-58366 - CVE House
Back to Database
Status published Critical CVE-2025-58366

Onyxia private helm repository credentials are leaked through unauthenticated API

Vulnerability Description

Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58366

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

onyxia
Vulnerable Versions:
>= 4.6.0, < 4.9.0

Timeline

Official Publish: September 5th, 2025
Last Modified: September 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)