Description
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that same artifact. When global OCI signature verification was enabled via `OCI_TRUST_POLICY` (`enabled: true`), an attacker with write access to the configured OCI tag could publish an unsigned or improperly signed artifact containing `.doco-cd.yml` with `oci.verify: false`. This could cause signature verification to be bypassed and untrusted deployment content to be applied. This primarily impacts users deploying from OCI artifacts where deployment config is read from artifact contents (for example, poll/webhook flows without trusted inline deployment overrides). The issue is fixed by enforcing a strict trust boundary and no-downgrade behavior. First, artifact-contained `.doco-cd.yml` is treated as untrusted for OCI trust-policy override decisions. Second, if global `OCI_TRUST_POLICY.enabled` is `true`, per-deployment `oci.verify: false` cannot disable verification. Some workarounds are available. Do not source deployment config from untrusted OCI artifact contents. Use trusted inline `POLL_CONFIG.deployments` and avoid relying on artifact-contained trust-policy overrides. Restrict write/push permissions for OCI repositories/tags used by doco-cd. Prefer immutable digest pinning and protected release/tag workflows. Monitor for unexpected artifact digest changes and failed/suspicious verification events.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Deployment Trust Violation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Doco‑CD arises when global OCI signature verification is enabled. An attacker with write access to the configured OCI tag can publish an artifact that contains a .doco-cd.yml file setting oci.verify: false. Because of a trust‑boundary flaw, this configuration overrides the global OCI_TRUST_POLICY.enabled setting and disables signature verification, allowing malicious or unsigned deployment content to be pipeline accepts and runs untrusted container images or services, potentially compromising the hosts the applications they serve.

Affected Systems

The Kimdre Doco‑CD GitOps continuous‑delivery tool is affected. All releases before version 0.90.1 contain the flaw; releases 0.90.1 and later include the fix that treats artifact‑contained .doco-cd.yml as untrusted and blocks undesired verification overrides.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% flaw is not listed in CISA KEV. To exploit, an attacker must have write or push permissions to the configured OCI tag. With those rights, the attacker can publish an unsigned or improperly signed artifact containing a .doco-cd.yml file setting oci.verify: false, which bypasses the global OCI_TRUST_POLICY.enabled verification, allowing untrusted deployment content to be applied.

Generated by OpenCVE AI on September 15, 2026 at 20:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Doco‑CD to version 0.90.1 or newer to enforce the strict trust boundary.
  • Restrict OCI registry write/push permissions on the tags used by Doco‑CD, and disable loading deployment configuration from OCI artifact contents; instead, use trusted inline POLL_CONFIG.deployments or external encrypted configuration sources.
  • Enforce immutable digest pinning protected release/tag workflows to prevent unauthorized artifact updates.
  • Monitor for unexpected artifact digest changes and failed or suspicious signature verification events and alert on anomalies.

Generated by OpenCVE AI on September 15, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Kimdre
Kimdre doco-cd
Vendors & Products Kimdre
Kimdre doco-cd

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that same artifact. When global OCI signature verification was enabled via `OCI_TRUST_POLICY` (`enabled: true`), an attacker with write access to the configured OCI tag could publish an unsigned or improperly signed artifact containing `.doco-cd.yml` with `oci.verify: false`. This could cause signature verification to be bypassed and untrusted deployment content to be applied. This primarily impacts users deploying from OCI artifacts where deployment config is read from artifact contents (for example, poll/webhook flows without trusted inline deployment overrides). The issue is fixed by enforcing a strict trust boundary and no-downgrade behavior. First, artifact-contained `.doco-cd.yml` is treated as untrusted for OCI trust-policy override decisions. Second, if global `OCI_TRUST_POLICY.enabled` is `true`, per-deployment `oci.verify: false` cannot disable verification. Some workarounds are available. Do not source deployment config from untrusted OCI artifact contents. Use trusted inline `POLL_CONFIG.deployments` and avoid relying on artifact-contained trust-policy overrides. Restrict write/push permissions for OCI repositories/tags used by doco-cd. Prefer immutable digest pinning and protected release/tag workflows. Monitor for unexpected artifact digest changes and failed/suspicious verification events.
Title Doco-CD has an OCI Trust Policy Bypass via Artifact-Contained Configuration
Weaknesses CWE-347
CWE-501
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:34:38.420Z

Reserved: 2026-06-12T16:25:43.085Z

Link: CVE-2026-54248

cve-icon Vulnrichment

Updated: 2026-09-14T18:34:32.270Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:38.353

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-54248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-501

    Trust Boundary Violation