Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92615— Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed

Quick assessment

Affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 flightctl 中发现了一个漏洞。 worker 中的 函数会为每个仓库构建一个独立的 (其中可能包含 、自定义 CA 捆绑包或租户提供的 mTLS 客户端证书),并通过 将其安装到 go-git 的进程级全局 映射中。由于该 worker 从共享的 goroutine 池中并发地为多个组织渲染设备,因此在所有正在进行的 调用中,最后写入的租户仓库配置将生效。 这一竞态条件可能导致某个租户的 TLS 配置(包括 或 mTLS 客户端凭据)泄露到另一个租户的 Git 操作中。

CVSS 6.6 · Medium

Possible ATT&CK Techniques 1 AI

T1560 · Archive Collected Data
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol("https", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
资源加锁不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Edge Manager 1 - cpe:/a:redhat:edge_manager:1

II. Public POCs for CVE-2026-92615

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92615

登录查看更多情报信息。

Vendor Advisories for CVE-2026-92615 (1)

Other References for CVE-2026-92615 (1)

Same Patch Batch · Red Hat · 2026-09-16 · 9 CVEs total

CVE-2026-74909 8.1 HIGH Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo
CVE-2026-79651 7.5 HIGH Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching
CVE-2026-18212 7.5 HIGH Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state
CVE-2026-42784 7.4 HIGH Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio
CVE-2026-17526 7.2 HIGH Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t
CVE-2026-92358 6.4 MEDIUM Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil
CVE-2026-92091 5.9 MEDIUM Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops
CVE-2026-19607 5.3 MEDIUM Keycloak-services: keycloak-services: broker-originated username collision causes account

IV. Related Vulnerabilities

V. Comments for CVE-2026-92615

No comments yet


Leave a comment