OpenShift oc-mirror CVE-2026-75939 can poison disconnected registries
CVE-2026-75939 lets RHEL 9 OpenShift oc-mirror accept forged PGP signatures and mirror malicious releases into disconnected registries; no errata yet.
Red Hat disclosed CVE-2026-75939, an important flaw in the OpenShift oc-mirror plugin for RHEL 9, scored CVSS v3.1 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). GBHackers calls that score preliminary, while Cyber Security News reports 7.4 without that qualifier. Both say the tool checks PGP signature errors before finishing the signed body, so a forged message that still cites a valid Red Hat release key can be treated as trusted. An attacker who can tamper with or alter traffic to the signature endpoint—no privileges required, but high complexity—could mirror malicious release images into a disconnected registry as trusted content. The RHEL 8 plugin is not affected. At the September 21, 2026 disclosure, Red Hat had not issued a security erratum, and both outlets say no mitigation met Red Hat’s criteria.
- CVE-2026-75939 is an important flaw in the OpenShift oc-mirror plugin on RHEL 9; both reports say the RHEL 8 plugin is unaffected.
- CVSS v3.1 is 7.4 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). GBHackers calls the score preliminary; Cyber Security News does not.
- The plugin checks PGP signature errors before processing the full signed body, so a forged message that still references a valid Red Hat release key can be accepted.
- Exploitation needs tampering with or altered traffic to the signature endpoint, requires no privileges, and is high complexity.
- Mirrored release images can then enter a disconnected registry as trusted content.
- As of the September 21, 2026 disclosure, Red Hat had issued no security erratum, and both reports say no mitigation met Red Hat’s criteria.
Coverage timelineoldest first · each row is one article
- · 5d agoRed Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
GBHackers· 64
OpenShift oc-mirror flaw CVE-2026-75939 can bypass release signature checks and poison disconnected registries.
- · 4d agoRed Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases
Cyber Security News· 54
Red Hat OpenShift oc-mirror can accept forged PGP signatures, letting attackers mirror malicious release images into disconnected registries.
Vulnerabilities in this storyAll →
- CVE-2026-759397.4—PGP Signature Verification Bypass in OpenShift oc-mirrorpublished · openshift oc-mirror
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-75939 | PGP Signature Verification Bypass in OpenShift oc-mirror CVE-2026-75939 is a signature verification bypass vulnerability in the openshift/oc-mirror tool. The flaw is triggered when the tool incorrectly processes PGP release image signatures, allowing an attacker to forge a signature that appears valid. A remote attacker could intercept network traffic to supply a malicious payload, bypassing verification to mirror a compromised software release into a disconnected registry. This directly threatens the integrity of software deployments in affected OpenShift environments. There is no known public proof-of-concept or active exploitation in the wild. Do: Upgrade oc-mirror to a version that includes a fix for CVE-2026-75939. Verify the integrity of your mirrored software payloads. Monitor Red Hat and upstream security advisories for updates. |