在 flightctl 中发现了一个漏洞。 worker 中的 函数会为每个仓库构建一个独立的 (其中可能包含 、自定义 CA 捆绑包或租户提供的 mTLS 客户端证书),并通过 将其安装到 go-git 的进程级全局 映射中。由于该 worker 从共享的 goroutine 池中并发地为多个组织渲染设备,因此在所有正在进行的 调用中,最后写入的租户仓库配置将生效。 这一竞态条件可能导致某个租户的 TLS 配置(包括 或 mTLS 客户端凭据)泄露到另一个租户的 Git 操作中。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2 | - |
cpe:/a:redhat:acm:2
|
|
| Red Hat | Red Hat Edge Manager 1 | - |
cpe:/a:redhat:edge_manager:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74909 | 8.1 HIGH | Keycloak-services: keycloak-services: incomplete fix for cve-2026-15573 allows policy enfo |
| CVE-2026-79651 | 7.5 HIGH | Keycloak-services: keycloak-services: unauthenticated dos via unbounded locale caching |
| CVE-2026-18212 | 7.5 HIGH | Keycloak-services: keycloak-services: saml redirect deflate helpers leak native zlib state |
| CVE-2026-42784 | 7.4 HIGH | Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key flag confusio |
| CVE-2026-17526 | 7.2 HIGH | Keycloak-services: keycloak-services: privilege escalation via impersonation role allows t |
| CVE-2026-92358 | 6.4 MEDIUM | Keycloak-services: keycloak-services: residual cross-browser account-link proof allows sil |
| CVE-2026-92091 | 5.9 MEDIUM | Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops |
| CVE-2026-19607 | 5.3 MEDIUM | Keycloak-services: keycloak-services: broker-originated username collision causes account |
No comments yet