Red HatCVE-2026-96577
Red Hat oc-mirror. During mirroring operations: missing authentication
High7.1CVE-2026-96577 · Published Oct 1, 2026 · updated Oct 6, 2026
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 Product | all versions | No fix yet |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat OpenShift Container Platform 4: open redirect | Medium6.1 | No fix yet |
| Oct 1 | Red Hat GEGL: out-of-bounds read | Medium5.5 | No fix yet |
| Sep 30 | Red Hat Enterprise Linux: request smuggling | Medium5.3 | No fix yet |
| Sep 30 | Assisted Installer for Red Hat OpenShift Container Platform : path traversal | High7.3 | No fix yet |
| Sep 30 | A trust-boundary flaw in CRI-O's sandbox state persistence | High7.8 | No fix yet |
| Sep 30 | Red Hat rpm. RPMTAG_FILESIGNATURES: heap buffer overflow | High7.1 | No fix yet |