A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote a
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | any |
unaffected |
any |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| Red Hat | Red Hat OpenShift Container Platform 4 | - |
cpe:/a:redhat:openshift:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92574 | 8.8 HIGH | Cri-o: cri-o checkpoint restore bypasses destination security context |
| CVE-2026-80110 | 8.1 HIGH | Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent |
| CVE-2026-15801 | 8.0 HIGH | Cri-o: cri-o: insufficient validation during container checkpoint restore |
| CVE-2026-94449 | 7.5 HIGH | Quarkus-smallrye-fault-tolerance: quarkus-smallrye-fault-tolerance: memory leak in @applyg |
| CVE-2026-94368 | 7.1 HIGH | Noobaa-core: noobaa-core: presigned put url escalation to copyobject via unsigned x-amz-co |
| CVE-2026-94215 | 5.5 MEDIUM | Keycloak-services: keycloak-services: cross-realm client read/write via request-level cach |
| CVE-2026-93433 | 5.5 MEDIUM | Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd pa |
| CVE-2026-94213 | 4.9 MEDIUM | Keycloak-services: keycloak-services: authorization services policy evaluation endpoint le |
| CVE-2026-92382 | 4.1 MEDIUM | Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads t |
| CVE-2026-94217 | 3.5 LOW | Keycloak-services: keycloak-services: uma scope merge across resource owners via resource |
| CVE-2026-94218 | 3.1 LOW | Keycloak-services: keycloak-services: 2fa setup enforcement bypass via authentication sess |
| CVE-2026-94184 | Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-202 |
No comments yet