Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-96577
Red Hat Red Hat OpenShift Container Platform 4.19 — Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled
AV AC PR UI S C I A CVSS EPSS %ile KEV
A L N N U L H N 7.1 .0021 9.6 —
AFFECTED
Product Versions Fixed
Red Hat OpenShift Container Platform 4.19 unspecified 1790778095
Red Hat OpenShift Container Platform 4.20 unspecified 1790782357
Red Hat OpenShift Container Platform 4.21 unspecified 1790777129
Red Hat OpenShift Container Platform 4.22 unspecified 1790775357
Assisted Installer for Red Hat OpenShift Container Platform 2 unspecified —
TIMELINE
Sep 23 Reserved by redhat
Oct 1 Published (CNA: redhat)
Oct 5 PATCH SHIPPED — CVE-2026-96577 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790777129.
Description
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 23, 2026 | Reserved | Reserved by redhat |
| October 1, 2026 | Published | Published (CNA: redhat) |
| October 5, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-96577 (Red Hat OpenShift Container Platform 4.21). Fixed in Red Hat OpenShift Container Platform 4.21 1790777129. |
Affected
Affected products and packages — 5 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | — | — | 1790778095 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | — | — | 1790782357 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | — | — | 1790777129 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | — | — | 1790775357 |
| Red Hat | Assisted Installer for Red Hat OpenShift Container Platform 2 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-96577 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.