{"id":"CVE-2026-92615","published":"2026-09-16T16:17:23.513","lastModified":"2026-09-17T16:18:32.773","description":"A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol(\"https\", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. \nThis race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.","cvssScore":6.6,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N","cwes":["CWE-413"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-92615","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2518323","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}