Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87058

Опубликовано: 08 сент. 2026
Источник: redhat
CVSS3: 2.6

Описание

A flaw was found in olm-operator-konflux-sample. The hermetic build mode is disabled by default, allowing bundle builds to perform live network fetches. This means that external, unverified resources can be pulled during the build process, potentially compromising the integrity and trustworthiness of the resulting software artifacts. This introduces a supply chain risk where the final product might contain unintended or malicious code.

Отчет

This issue has a Low impact on Red Hat Konflux CI. The default configuration of shared pipelines in olm-operator-konflux-sample disables hermetic builds, allowing live network fetches during bundle creation. This introduces a potential supply chain risk by relying on external, unverified inputs during the build process, rather than affecting the runtime security of deployed applications.

Меры по смягчению последствий

To reduce the risk of external interference during bundle builds, enable hermetic build mode within Konflux shared pipelines. This can be achieved by setting the hermetic default to "true" in the relevant pipeline configurations. Additionally, ensure prefetch-input is supplied for gatekeeper/gatekeeper-operator Go builds and replace dynamic skopeo inspect architecture detection with statically-declared architecture labels. Changes to pipeline configurations may require re-running affected builds.

Дополнительная информация

Статус:

Low
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2530055olm-operator-konflux-sample: olm-operator-konflux-sample: Hermetic build disabled by default; bundle build performs live network fetches

2.6 Low

CVSS3

2.6 Low

CVSS3

Уязвимость CVE-2026-87058