VDB

CVE-2026-96577

CVE-2026-96577 PUBLISHED CVSS 7.1 HIGH

Reported by redhat · Published October 1, 2026

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4.191790778095
Red HatRed Hat OpenShift Container Platform 4.201790782357
Red HatRed Hat OpenShift Container Platform 4.211790777129
Red HatRed Hat OpenShift Container Platform 4.221790775357
Red HatAssisted Installer for Red Hat OpenShift Container Platform 2
Red HatAssisted Installer for Red Hat OpenShift Container Platform 2
Red HatRed Hat OpenShift Container Platform 4.221790775357, 1790775357
Red HatRed Hat OpenShift Container Platform 4.211790777129, 1790777129
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.191790778095
Red HatRed Hat OpenShift Container Platform 4.201790782357, 1790782357

Timeline

  • Oct 1, 2026 Coalition ESS Score
  • Oct 1, 2026 CVE Published
  • Oct 2, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Security Advisory
  • Oct 8, 2026 Security Advisory
  • Oct 8, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›