NONE · 0

CVE-2026-11745

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an...

Vulnerability Description

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-11745?

CVE-2026-11745 is a documented vulnerability. A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an...

How severe is CVE-2026-11745?

CVSS scoring is not yet available for CVE-2026-11745. Check NVD for updates.

Is there a patch for CVE-2026-11745?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.