CVE-2026-96577: Red Hat Assisted Installer For Red Hat Openshift Container Platform 2

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.

Affected products

  • Red Hat Assisted Installer For Red Hat Openshift Container Platform 2
  • Red Hat Red Hat Openshift Container Platform 4.19: before 1790778095 (fixed in 1790778095)
  • Red Hat Red Hat Openshift Container Platform 4.20: before 1790782357 (fixed in 1790782357)
  • Red Hat Red Hat Openshift Container Platform 4.21: before 1790777129 (fixed in 1790777129)
  • Red Hat Red Hat Openshift Container Platform 4.22: before 1790775357 (fixed in 1790775357)

Published 2026-10-01. Last modified 2026-10-07.