CVE-2026-54248

Source
https://cve.org/CVERecord?id=CVE-2026-54248
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54248.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54248
Aliases
  • GHSA-5rv3-qpp3-6jp5
Published
2026-09-11T21:24:26Z
Modified
2026-09-13T03:45:17Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration
Details

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that same artifact. When global OCI signature verification was enabled via OCI_TRUST_POLICY (enabled: true), an attacker with write access to the configured OCI tag could publish an unsigned or improperly signed artifact containing .doco-cd.yml with oci.verify: false. This could cause signature verification to be bypassed and untrusted deployment content to be applied. This primarily impacts users deploying from OCI artifacts where deployment config is read from artifact contents (for example, poll/webhook flows without trusted inline deployment overrides). The issue is fixed by enforcing a strict trust boundary and no-downgrade behavior. First, artifact-contained .doco-cd.yml is treated as untrusted for OCI trust-policy override decisions. Second, if global OCI_TRUST_POLICY.enabled is true, per-deployment oci.verify: false cannot disable verification. Some workarounds are available. Do not source deployment config from untrusted OCI artifact contents. Use trusted inline POLL_CONFIG.deployments and avoid relying on artifact-contained trust-policy overrides. Restrict write/push permissions for OCI repositories/tags used by doco-cd. Prefer immutable digest pinning and protected release/tag workflows. Monitor for unexpected artifact digest changes and failed/suspicious verification events.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-347",
        "CWE-501"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54248.json"
}
References

Affected packages

Git / github.com/kimdre/doco-cd

Affected ranges

Type
GIT
Repo
https://github.com/kimdre/doco-cd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.90.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.1
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.11.0
v0.11.1
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.13.0
v0.13.0-rc.1
v0.13.1
v0.14.0
v0.15.0
v0.15.1
v0.15.2
v0.16.0
v0.17.0
v0.18.0
v0.19.0
v0.19.1
v0.2.0
v0.2.1
v0.20.0
v0.21.0
v0.21.1-rc.1
v0.21.1-rc.2
v0.22.0
v0.22.0-rc.1
v0.22.0-rc.2
v0.22.1-rc.1
v0.23.0
v0.24.0
v0.25.0
v0.25.1
v0.25.2
v0.26.0
v0.26.1
v0.26.1-rc.1
v0.27.0
v0.27.0-rc.1
v0.28.0
v0.28.1
v0.29.0
v0.29.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.30.0
v0.31.0
v0.31.1
v0.31.2
v0.32.0
v0.32.1
v0.33.0
v0.33.1
v0.34.0
v0.35.0
v0.36.0
v0.37.0
v0.37.1
v0.37.2
v0.37.3
v0.38.0
v0.39.0
v0.39.1
v0.4.0
v0.4.1
v0.40.0
v0.41.0
v0.42.0
v0.42.1
v0.43.0
v0.44.0
v0.45.0
v0.46.0
v0.47.0
v0.48.0
v0.49.0
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.50.0
v0.51.0
v0.51.1
v0.52.0
v0.53.0
v0.54.0
v0.54.1
v0.55.0
v0.56.0
v0.57.0
v0.58.0
v0.58.0-rc.1
v0.59.0
v0.6.0
v0.60.0
v0.61.0
v0.61.0-rc.2
v0.61.0-rc.3
v0.61.0-rc.4
v0.61.1
v0.62.0
v0.63.0
v0.64.0
v0.65.0
v0.65.1
v0.66.0
v0.67.0
v0.67.1
v0.68.0
v0.69.0
v0.69.1
v0.7.0
v0.7.1
v0.70.0
v0.71.0
v0.72.0
v0.72.1
v0.72.2
v0.72.3
v0.73.0
v0.73.1
v0.73.2
v0.74.0
v0.74.0-rc.1
v0.75.0
v0.76.0
v0.76.0-rc.1
v0.76.0-rc.2
v0.77.0
v0.77.0-rc.1
v0.77.0-rc.2
v0.78.0
v0.79.0
v0.8.0
v0.8.1
v0.80.0
v0.80.1
v0.81.0
v0.81.0-rc.1
v0.81.0-rc.2
v0.82.0
v0.82.0-rc.1
v0.82.1
v0.82.2
v0.83.0
v0.83.0-rc.1
v0.84.0
v0.84.0-rc.1
v0.84.0-rc.2
v0.84.0-rc.3
v0.85.0
v0.85.1
v0.86.0
v0.86.0-rc.1
v0.87.0
v0.88.0
v0.89.0
v0.89.0-rc.1
v0.89.0-rc.2
v0.89.0-rc.3
v0.89.1
v0.89.2
v0.9.0
v0.90.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54248.json"