CVE-2026-75939
7.4 HIGHPublished 2026-09-21 · Updated 2026-09-21
AI risk analysis
- Summary
- The flaw in openshift/oc-mirror allows for PGP signature verification bypass, enabling remote attackers to forge signatures and mirror malicious release payloads into a disconnected registry.
- Exploitability
- Exploitation requires intercepting or manipulating network traffic to the signature endpoint; preconditions include access to the network path between the attacker and the target system.
- Blast radius
- If exploited, this could compromise the integrity of software deployments in disconnected registries, leading to potential security breaches.
- Prioritized remediation
- Update openshift/oc-mirror to a patched version as soon as possible or disable PGP signature verification until a fix is available.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-347
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-15307PoC
- HIGHCVE-2026-15372
- HIGHCVE-2026-25703PoC
- MEDIUMCVE-2026-61612PoC
- MEDIUMCVE-2026-61749PoC
- HIGHCVE-2026-70369
- CRITICALCVE-2026-70376PoC
- HIGHCVE-2026-70482PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.