OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-75939

HIGH · CVSS 7.4 EPSS 0.31% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability in the `openshift/oc-mirror` tool allows for improper verification of PGP signatures, enabling remote attackers to bypass signature checks and inject malicious payloads into disconnected registries. This flaw compromises the integrity of software deployments by allowing crafted PGP messages with valid Red Hat release key IDs but forged signatures. Organizations using `oc-mirror` for managing software images should prioritize addressing this vulnerability to safeguard their deployment environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75939
Severity
HIGH
CVSS
7.4
EPSS
0.31%

Original NVD Description

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.