← Back to search

CVE-2026-75939

7.4 HIGH

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw in openshift/oc-mirror allows for PGP signature verification bypass, enabling remote attackers to forge signatures and mirror malicious release payloads into a disconnected registry.
Exploitability
Exploitation requires intercepting or manipulating network traffic to the signature endpoint; preconditions include access to the network path between the attacker and the target system.
Blast radius
If exploited, this could compromise the integrity of software deployments in disconnected registries, leading to potential security breaches.
Prioritized remediation
Update openshift/oc-mirror to a patched version as soon as possible or disable PGP signature verification until a fix is available.
pgpsignature-bypassregistrysecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-347

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.