Description
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Published: 2026-10-01
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Red Hat has not identified any known mitigations for this issue. Customers are advised to apply the available security update when released.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.19::el9
References

Tue, 06 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.20::el9
References

Tue, 06 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift:4.21::el9
cpe:/a:redhat:openshift:4.22::el9
References

Tue, 06 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 04 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Oc-mirror
Oc-mirror oc-mirror
Vendors & Products Oc-mirror
Oc-mirror oc-mirror

Thu, 01 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Title oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
First Time appeared Redhat
Redhat assisted Installer
Redhat openshift
CPEs cpe:/a:redhat:assisted_installer:2
cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat assisted Installer
Redhat openshift
References

Thu, 24 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Weaknesses CWE-306
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

threat_severity

Important


Subscriptions

Oc-mirror Oc-mirror
Redhat Assisted Installer Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T14:12:50.602Z

Reserved: 2026-09-23T13:30:40.232Z

Link: CVE-2026-96577

cve-icon Vulnrichment

Updated: 2026-10-06T00:04:53.564Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T10:17:17.760

Modified: 2026-10-07T15:17:59.377

Link: CVE-2026-96577

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-23T14:05:25Z

Links: CVE-2026-96577 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T20:47:51Z

Weaknesses