CPE
A logic flaw in the oc-mirror tool allows remote attackers to bypass PGP signature verification, enabling the injection of malicious release payloads into disconnected registries.