Red Hat OpenShift oc-mirror PGP signature bypass CVE-2026-75939 (CVSS 7.4) — malicious mirror into disconnected registries
Red Hat CVE-2026-75939 (published 21 September 2026): openshift/oc-mirror incorrectly verifies PGP release-image signatures by checking for signature errors before the entire signed body is processed, enabling a verification bypass. A remote attacker who can intercept/manipulate traffic to the signature endpoint can craft a PGP message with a valid Red Hat release key ID but a forged signature so oc-mirror accepts and mirrors a malicious release payload into a disconnected/air-gapped registry. Red Hat CVSS 3.1 7.4 High (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N), CWE-347. Primary: Red Hat CVE page; metadata: CVE.report; wire: Cyber Security News 22 Sep 2026.
- Product
- Red Hat OpenShift oc-mirror (openshift/oc-mirror) used to mirror releases/operators into private registries
- Versions
- See Red Hat CVE-2026-75939 product/package table for affected oc-mirror plugin builds; apply RH errata when listed for your OpenShift 4 train.
- CVSS
- (CVSS 3.1 High; Red Hat)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- Update oc-mirror to Red Hat-fixed builds per CVE-2026-75939; for air-gapped mirrors, verify release signatures out-of-band until patched; treat recently mirrored content as untrusted if signature path was MitM-capable; restrict who can run oc-mirror against production disconnected registries
Primary: Red Hat — CVE-2026-75939 oc-mirror PGP verification bypass · Vendor: Red Hat Product Security — CVE-2026-75939 · CVE: CVE-2026-75939 · CVE.report — CVE-2026-75939; also Cyber Security News 22 Sep 2026
