{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alinecorpcentraldogma/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:linecorp:centraldogma:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-11745"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["centraldogma-server-mirror-git (\u003c 0.84.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","git","ssh","mitm","cve-2026-11745"],"_cs_type":"advisory","_cs_vendors":["LINE Corporation"],"content_html":"\u003cp\u003eCentral Dogma (vulnerable version \u0026lt; 0.84.0) contains a critical security defect in its Git mirroring component, specifically within \u003ccode\u003eSshGitMirror.java\u003c/code\u003e. The application utilizes an Apache MINA SSHD \u003ccode\u003eServerKeyVerifier\u003c/code\u003e implementation that unconditionally returns \u003ccode\u003etrue\u003c/code\u003e for all outbound SSH connections. This effectively disables SSH host-key verification for \u003ccode\u003egit+ssh://\u003c/code\u003e mirrors.\u003c/p\u003e\n\u003cp\u003eThe application provides no mechanism for operators to enable host-key pinning or known-hosts verification. Consequently, the client blindly trusts any host key presented by a remote server during the initial handshake. This vulnerability, tracked as CVE-2026-11745, allows an on-path attacker to position themselves between the Central Dogma server and its upstream Git repository. Because Central Dogma is frequently used to store sensitive configurations, including database credentials and third-party API keys, successful exploitation leads to the complete compromise of the configuration store and subsequent supply-chain propagation to all dependent microservices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker achieves on-path network position via ARP spoofing, internal DNS poisoning, or BGP hijacking.\u003c/li\u003e\n\u003cli\u003eCentral Dogma initiates an outbound \u003ccode\u003egit+ssh\u003c/code\u003e connection to a configured upstream repository.\u003c/li\u003e\n\u003cli\u003eThe attacker intercepts the connection request and responds as a malicious SSH server.\u003c/li\u003e\n\u003cli\u003eThe victim's \u003ccode\u003eSshGitMirror\u003c/code\u003e client receives the attacker's ephemeral RSA host key and, due to the hardcoded \u003ccode\u003etrue\u003c/code\u003e return value in the verifier, accepts the host key without validation.\u003c/li\u003e\n\u003cli\u003eThe attacker completes the SSH handshake and proceeds to request authentication.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the client's credentials or public key fingerprints offered during the authentication phase.\u003c/li\u003e\n\u003cli\u003eIf exfiltrating, the attacker serves the contents of the mirrored repository to the client for inspection/storage.\u003c/li\u003e\n\u003cli\u003eIf injecting, the attacker provides arbitrary commits, which Central Dogma then propagates to all downstream services consuming the compromised configuration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk to organizational secrets, as Central Dogma is primarily used as a configuration management store. An attacker can intercept database credentials, certificates, and feature flags. Furthermore, because Central Dogma pushes updates to subscribing microservices, an attacker can push malicious configurations, causing a broad supply-chain compromise across the organization. The vulnerability has been confirmed reproducible via a \u003ccode\u003eparamiko\u003c/code\u003e-based fake SSH server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003ecom.linecorp.centraldogma:centraldogma-server-mirror-git\u003c/code\u003e to version 0.84.0 or later to mitigate CVE-2026-11745.\u003c/li\u003e\n\u003cli\u003eAudit existing Git mirror configurations to identify if attackers could have already intercepted traffic, given the lack of historical host-key verification.\u003c/li\u003e\n\u003cli\u003eImplement host-key fingerprinting for all internal Git repositories to support the new pinning functionality introduced in the patched version.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T00:58:05Z","date_published":"2026-09-12T00:58:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ssh-host-key-bypass/","summary":"Central Dogma's Git mirror SSH client disables host-key verification, allowing on-path attackers to perform Man-in-the-Middle (MitM) attacks to exfiltrate sensitive configuration data or inject malicious commits.","title":"Unconditional SSH Host-Key Trust in Central Dogma Git Mirror","url":"https://feed.craftedsignal.io/briefs/2026-09-ssh-host-key-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:linecorp:centraldogma:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}