Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Red Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases

Red Hat has disclosed an Important security vulnerability in the OpenShift oc-mirror tool that could allow attackers to bypass PGP signature verification and introduce malicious release images into disconnected OpenShift environments. Tracked as CVE-2026-75939, the issue carries a CVSS v3. 1 score of 7. 4 and was made public on September 21, 2026. The flaw affects the openshift/oc-mirror component, which organizations use to copy OpenShift release images, operator catalogs, and related content into private registries. This process is particularly important for air-gapped or disconnected deployments, where systems cannot download software directly from Red Hat registries or the public internet. According to Red Hat, oc-mirror incorrectly validates PGP-signed release image signatures. The tool checks for signature errors before it has finished processing the entire signed message body.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Red Hat OpenShift Flaw Lets Attackers Bypass Signature Checks and Inject Malicious Release Images

Red Hat has disclosed an Important OpenShift vulnerability that could allow attackers to bypass release-image signature verification and insert malicious payloads into disconnected registries. Tracked as CVE-2026-75939, the issue affects the oc-mirror utility and carries a CVSS v3. 1 score of 7. 4. The flaw stems from an error in how openshift/oc-mirror validates PGP-signed OpenShift release images. The utility checks for a signature error before processing the complete signed message body. Red Hat OpenShift Flaw That ordering defect can cause the signature-verification process to accept a crafted PGP message even though its signature is forged. An attacker would need to intercept or manipulate traffic between oc-mirror and the endpoint used to retrieve release signatures.

·CyberPress
Read →

You've reached the end of current stories for this search.