Bug 2523077 (CVE-2026-96577)

Summary: CVE-2026-96577 oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerability-draftAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgamliel, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, sbratsla, security-response-team, sghai, sidsharm, suppawar, vlaad
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-24 19:29:16 UTC
## Embedded cache registry binds to all interfaces with no authentication

**CWEs:** CWE-306, CWE-668
**CVSS:** 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N)
**Component:** openshift-4.21-payload/oc-mirror__release-4.21

### Description
setupLocalRegistryConfig() renders a distribution/v3 registry configuration whose HTTP listener is `addr: :{{ .LocalStoragePort }}` (default 55000). Because no host is specified the Go net/http stack binds 0.0.0.0/[::]. The htpasswd auth block is commented out, delete is enabled, and TLS is not configured. The registry is started via LocalStorageService.ListenAndServe() for the full duration of mirrorToDisk / diskToMirror runs, which on large payloads can be hours. The separate isLocalStoragePortBound() probe dials `localhost:%d`, masking the fact that the actual server is not loopback-restricted.

### Affected Locations
- `:`
- `:`
- `:`

### Evidence
**internal/pkg/cli/executor.go:640-648 — registry config template binds to ':<port>' with auth commented out**
```go
http:
  addr: :{{ .LocalStoragePort }}
  headers:
    X-Content-Type-Options: [nosniff]
      #auth:
      #htpasswd:
      #realm: basic-realm
      #path: /etc/registry
```

### Attack Pattern
Adjacent-network host → push tampered image blobs into the operator's local cache registry, or pull mirrored Red Hat content, while oc-mirror is running.

---
*Source: Ex-Wing security assessment, finding FIND-001*