CVE-2026-75939
Received Received - Intake

PGP Signature Verification Bypass in oc-mirror

Vulnerability report for CVE-2026-75939, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: redhat-SADP

Description

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-21
AI Q&A
2026-09-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat oc-mirror *
red_hat oc_mirror *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the openshift/oc-mirror tool. It incorrectly verifies PGP release image signatures by checking for errors before processing the entire signed body. This allows attackers to bypass signature verification by forging a PGP message with a valid Red Hat key ID but a fake signature. The tool may then accept and mirror a malicious release payload into a disconnected registry, compromising software integrity.

Detection Guidance

Detecting this vulnerability requires monitoring network traffic and verifying PGP signature handling in oc-mirror. Check if oc-mirror processes PGP messages before fully consuming the signed body. Inspect logs for signature errors or unexpected key ID matches. No direct commands are provided in the resources, but network monitoring tools like tcpdump or Wireshark could help analyze traffic to the signature endpoint.

Impact Analysis

An attacker could intercept or manipulate network traffic to the signature endpoint and trick oc-mirror into accepting a malicious release payload. This could compromise the integrity of software deployments in disconnected environments, potentially leading to unauthorized or malicious software being installed.

Compliance Impact

This vulnerability could lead to unauthorized software deployments, violating integrity requirements in standards like GDPR and HIPAA. Compromised software integrity may result in non-compliance with data protection and security regulations, potentially leading to legal and operational consequences.

Mitigation Strategies

Monitor official Red Hat advisories for updates or patches. Avoid using oc-mirror in disconnected environments until a fix is available. Restrict network access to signature endpoints and validate all mirrored payloads manually if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75939. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart