Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87056

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 2.6

Описание

A flaw was found in operator-sdk-builder. The repository lacks automated dependency-update configurations for its git submodules, Containerfile base image, and Tekton bundle references. This absence prevents the automatic flagging of stale or vulnerable dependencies. Consequently, this could lead to the inclusion of known vulnerable components in the build process, increasing the risk of security exposures.

Отчет

This issue has a Low impact as it describes the absence of automated dependency update configurations within the operator-sdk-builder component of Konflux CI. This lack of automation means that stale or vulnerable dependencies may not be automatically identified, increasing the risk of introducing security flaws if not manually managed. It does not represent an immediately exploitable vulnerability in deployed Red Hat products but rather a preventative measure for development practices.

Меры по смягчению последствий

To mitigate the risk of stale or vulnerable dependencies, configure automated dependency updates for the operator-sdk-builder component. This can be achieved by adding a renovate.json file or enabling Konflux MintMaker rules to cover git-submodules, dockerfile, and tekton managers. Implementing these configurations will ensure that submodule SHAs and base-image digests receive automated update pull requests, proactively addressing potential future vulnerabilities.

Дополнительная информация

Статус:

Low
Дефект:
CWE-1104
https://bugzilla.redhat.com/show_bug.cgi?id=2530047operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile

2.6 Low

CVSS3

2.6 Low

CVSS3

Уязвимость CVE-2026-87056