Advisories for Golang/Github.com/Siderolabs/Omni package

2025

Omni Wireguard SideroLink potential escape

This vulnerability creates two distinct attack scenarios based on Omni's IP forwarding configuration. IP Forwarding Disabled (Default) If IP forwarding is disabled, an attacker on a Talos machine can send packets over SideroLink to any listening service on Omni itself (e.g., an internal API). If Omni is running in host networking mode, any service on the host machine could also be targeted. While this is the default configuration, Omni does …