Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87055

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 2.6

Описание

A flaw was found in operator-sdk-builder. The software uses a flexible label, called a mutable tag, to identify its base container image instead of a unique, fixed identifier. This practice allows the underlying base image to change unexpectedly between builds. Such a change could introduce vulnerabilities or malicious code into the build process, posing a supply chain integrity risk.

Отчет

This issue has a Low impact as it primarily affects the integrity of the build process rather than introducing a runtime vulnerability in deployed applications. Referencing base images with mutable tags can lead to inconsistent builds if the underlying image changes, potentially introducing unexpected behavior or dependencies.

Меры по смягчению последствий

To mitigate this issue, ensure that the FROM line in the Containerfile references the base image using an immutable SHA256 digest instead of a mutable tag. For example, update the FROM line to FROM registry.access.redhat.com/ubi9/go-toolset:1.25.5-1770654497@sha256:<digest>. This practice ensures that the base image remains consistent across builds, improving build integrity. This change requires modifying the Containerfile and rebuilding the image.

Дополнительная информация

Статус:

Low
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2530046operator-sdk-builder: operator-sdk-builder: Base image referenced by mutable tag rather than sha256 digest

2.6 Low

CVSS3

2.6 Low

CVSS3

Уязвимость CVE-2026-87055