Red Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases
Red Hat OpenShift oc-mirror can accept forged PGP signatures, letting attackers mirror malicious release images into disconnected registries.
Red Hat disclosed CVE-2026-75939, a CVSS 7.4 flaw in the OpenShift oc-mirror plugin for RHEL 9. The tool checks PGP signature errors before finishing the signed message, so a forged message carrying a valid Red Hat release key ID can be accepted. An attacker who can alter traffic to the signature endpoint could mirror a malicious release image into a disconnected registry. No mitigation met Red Hat’s criteria at the September 21, 2026 disclosure, and the RHEL 8 plugin is not affected.
54