Intel

AIKIDO-2025-11007

github.com/opencost/opencost is vulnerable to Inadequate Encryption Strength

Inadequate Encryption Strength Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 30, 2025

30

Low Risk

This Affects:

GOgithub.com/opencost/opencost
0.0.1 - 1.118.0
Fixed in 1.119.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow the use of insecure TLS 1.0 and TLS 1.1 protocols, exposing communications to man-in-the-middle attacks. This vulnerability compromises the confidentiality and integrity of data by enabling attackers to intercept and manipulate the data being transmitted.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your configurations allow for TLS 1.0 or TLS 1.1.

Background info

github.com/opencost/opencost is vulnerable to Inadequate Encryption Strength in versions 0.0.1 - 1.118.0.

How to fix this

Upgrade the github.com/opencost/opencost library to the patch version or strengthen TLS configuration to use TLS 1.2 or higher.