Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
OpenShift oc-mirror flaw CVE-2026-75939 can bypass release signature checks and poison disconnected registries.
Red Hat disclosed CVE-2026-75939, an important flaw in the OpenShift oc-mirror tool with a preliminary CVSS v3.1 score of 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). The RHEL9 oc-mirror plugin checks PGP signature errors before processing the full signed body, so an attacker who can tamper with the signature endpoint can present a forged signature that still appears to reference a valid Red Hat release key. Mirrored release images can then enter a disconnected registry as trusted content. No security erratum is available and Red Hat says no mitigation meets its criteria; the RHEL8 plugin is unaffected.