oc-mirror CVE-2026-75939: PGP signature check runs before the message is processed
Red Hat disclosed CVE-2026-75939 (CVSS 7.4) in the oc-mirror plugin for OpenShift Container Platform 4: a validation-order flaw lets the tool accept a forged PGP message carrying a legitimate Red Hat release key id. An attacker only needs to intercept traffic to the signature endpoints, after which a malicious release payload is synced into a private registry in a disconnected environment. No practical mitigation was available at disclosure.
- CVSS 7.4; openshift4/oc-mirror-plugin-rhel9 in OCP 4 affected, RHEL 8 variant is not
- Signature error check completes before the full signed message body is processed
- Requires traffic interception to signature endpoints; no privileges or user interaction
- Result: malicious image in a private registry and possible code execution in the cluster
Read next
Security