chiprook
← Security
SecurityOctober 5, 2026, 08:00

oc-mirror CVE-2026-75939: PGP signature check runs before the message is processed

Red Hat disclosed CVE-2026-75939 (CVSS 7.4) in the oc-mirror plugin for OpenShift Container Platform 4: a validation-order flaw lets the tool accept a forged PGP message carrying a legitimate Red Hat release key id. An attacker only needs to intercept traffic to the signature endpoints, after which a malicious release payload is synced into a private registry in a disconnected environment. No practical mitigation was available at disclosure.

oc-mirror CVE-2026-75939: PGP signature check runs before the message is processed
#RedHat#OpenShift#Oc-mirror
Read next
Security

Red Hat warns AI is driving a surge in cyber threats and faster exploits

Security

Researchers forged RSA signatures without cracking the key

Security

New RSA attack breaks signatures without factoring the key

Security

Linux distributions roll out batch of security updates