{"id":"CVE-2026-75939","published":"2026-09-21T15:17:31.520","lastModified":"2026-09-21T15:17:31.520","description":"A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.","cvssScore":7.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-347"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-75939","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517976","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in openshift/oc-mirror allows for PGP signature verification bypass, enabling remote attackers to forge signatures and mirror malicious release payloads into a disconnected registry.","exploitability":"Exploitation requires intercepting or manipulating network traffic to the signature endpoint; preconditions include access to the network path between the attacker and the target system.","blast_radius":"If exploited, this could compromise the integrity of software deployments in disconnected registries, leading to potential security breaches.","remediation":"Update openshift/oc-mirror to a patched version as soon as possible or disable PGP signature verification until a fix is available.","tags":["pgp","signature-bypass","registry","security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:15:39.530Z"}}