PT-2026-25851 · Romeo · Romeo

Virb3

·

Published

2026-03-16

·

Updated

2026-03-27

·

CVE-2026-32737

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Romeo versions prior to 0.2.1
Description Romeo is a tool designed to measure code coverage for Go applications within GitHub Actions. A misconfigured NetworkPolicy allows a malicious actor to move from the "hardened" namespace to any other Pod, breaking the expected security-by-default behavior and potentially enabling lateral movement. The issue stems from a mis-written NetworkPolicy.
Recommendations Update to version 0.2.1 or later. If updates are not possible, manually delete the inter-ns NetworkPolicy. Delete any failing network policy prefixed by inter-ns- in the target namespace.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-32737
GHSA-FGM3-Q9R5-43V9
GO-2026-4714
SUSE-SU-2026:1135-1

Affected Products

Romeo