Bug 2523077 (CVE-2026-96577) - CVE-2026-96577 oc-mirror__release-4.21: Embedded local cache registry listens on all interfaces without authentication, with delete enabled
Summary: CVE-2026-96577 oc-mirror__release-4.21: Embedded local cache registry listens...
Keywords:
Status: NEW
Alias: CVE-2026-96577
Product: Security Response
Classification: Other
Component: vulnerability-draft
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-24 19:29 UTC by OSIDB Bzimport
Modified: 2026-09-23 14:18 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-24 19:29:16 UTC
## Embedded cache registry binds to all interfaces with no authentication

**CWEs:** CWE-306, CWE-668
**CVSS:** 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N)
**Component:** openshift-4.21-payload/oc-mirror__release-4.21

### Description
setupLocalRegistryConfig() renders a distribution/v3 registry configuration whose HTTP listener is `addr: :{{ .LocalStoragePort }}` (default 55000). Because no host is specified the Go net/http stack binds 0.0.0.0/[::]. The htpasswd auth block is commented out, delete is enabled, and TLS is not configured. The registry is started via LocalStorageService.ListenAndServe() for the full duration of mirrorToDisk / diskToMirror runs, which on large payloads can be hours. The separate isLocalStoragePortBound() probe dials `localhost:%d`, masking the fact that the actual server is not loopback-restricted.

### Affected Locations
- `:`
- `:`
- `:`

### Evidence
**internal/pkg/cli/executor.go:640-648 — registry config template binds to ':<port>' with auth commented out**
```go
http:
  addr: :{{ .LocalStoragePort }}
  headers:
    X-Content-Type-Options: [nosniff]
      #auth:
      #htpasswd:
      #realm: basic-realm
      #path: /etc/registry
```

### Attack Pattern
Adjacent-network host → push tampered image blobs into the operator's local cache registry, or pull mirrored Red Hat content, while oc-mirror is running.

---
*Source: Ex-Wing security assessment, finding FIND-001*


Note You need to log in before you can comment on or make changes to this bug.