{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ared_hatoc_mirror/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:oc_mirror:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-75939"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["oc-mirror"],"_cs_severities":["high"],"_cs_tags":["supply-chain-security","cloud","red-hat","openshift"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-75939 involves a critical logic vulnerability in the \u003ccode\u003eoc-mirror\u003c/code\u003e tool, which is used to manage disconnected OpenShift environments. The tool incorrectly verifies PGP release image signatures by executing signature error checks before the entire signed body is fully processed. This premature validation allows a remote attacker, capable of intercepting or manipulating network traffic (e.g., via Man-in-the-Middle techniques), to present a PGP message that contains a valid Red Hat release key ID but a forged signature body. Because the tool fails to validate the entire payload, it accepts the tampered release as legitimate. This vulnerability significantly impacts the software supply chain integrity by allowing the mirroring of malicious container images into internal, disconnected enterprise registries, where they may later be deployed into production clusters.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for the unauthorized injection of malicious software components into isolated container registries. If exploited, an attacker can compromise the integrity of software deployments within an organization's internal infrastructure, potentially leading to arbitrary code execution across clusters that rely on the compromised mirror as a trusted source of truth.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for unauthorized or unexpected modifications to release image signatures or payloads being mirrored into disconnected registries.\u003c/li\u003e\n\u003cli\u003eImplement and enforce strict TLS validation for all network connections involved in the image mirroring process to mitigate potential interception of signature endpoints.\u003c/li\u003e\n\u003cli\u003ePatch the \u003ccode\u003eoc-mirror\u003c/code\u003e tool immediately once an official update is provided by Red Hat to address the signature verification logic flaw.\u003c/li\u003e\n\u003cli\u003eAudit internal container registry logs for image layers that originated from unexpected network sources or that lack valid, verifiable cryptographic signatures.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T16:29:19Z","date_published":"2026-09-21T16:29:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openshift-oc-mirror-pgp-bypass/","summary":"A logic flaw in the oc-mirror tool allows remote attackers to bypass PGP signature verification, enabling the injection of malicious release payloads into disconnected registries.","title":"CVE-2026-75939 - Signature Verification Bypass in Red Hat oc-mirror","url":"https://feed.craftedsignal.io/briefs/2026-09-openshift-oc-mirror-pgp-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:red_hat:oc_mirror:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}