VDB
CVE-2026-96577
CVE-2026-96577
PUBLISHED
CVSS 7.1 HIGH
Reported by redhat · Published October 1, 2026
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790778095 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790782357 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790777129 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790775357 |
| Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | |
| Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790775357, 1790775357 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790777129, 1790777129 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790778095 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790782357, 1790782357 |
Timeline
- Oct 1, 2026 Coalition ESS Score
- Oct 1, 2026 CVE Published
- Oct 2, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
- Oct 7, 2026 CVE Updated
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Security Advisory
- Oct 8, 2026 Security Advisory
- Oct 8, 2026 Security Advisory
References
- RHSA-2026:74380 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74383 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74429 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74434 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2523077 issue-trackingx_refsource_REDHAT