Description
A flaw was found in operator-sdk-builder. The software uses a flexible label, called a mutable tag, to identify its base container image instead of a unique, fixed identifier. This practice allows the underlying base image to change unexpectedly between builds. Such a change could introduce vulnerabilities or malicious code into the build process, posing a supply chain integrity risk.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Supply chain integrity risk via mutable tag use
Action: Patch
AI Analysis

Impact

The flaw in operator-sdk-builder permits referencing its base container image with a mutable tag rather than a stable sha256 digest. This practice allows the underlying image to change between builds, which could silently introduce vulnerabilities or malicious code into the build process. The impact is a supply‑chain integrity compromise, exposing builds to unintended code injection or vulnerability escalation.

Affected Systems

operator-sdk-builder is affected. No specific vendor or product version details were provided in the audit. Users should verify whether their installed operator-sdk-builder instance resolves base images via mutable tags.

Risk and Exploitability

The vulnerability received a CVSS score of 2.6, indicating low severity, and is not listed in CISA's KEV catalog. No EPSS score is available, but the inherent risk lies in the potential for supply‑chain tampering rather than direct exploitation. Attackers likely need to influence the container registry or supply a malicious image under a mutable tag to affect the build, a condition that could arise if registry access is not restricted or provenance checks are absent.

Generated by OpenCVE AI on September 9, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade operator-sdk-builder to a release that pins base images using immutable sha256 digests.
  • Configure build pipelines to enforce immutable tags or digests for all container references.
  • Enable image provenance verification and vulnerability scanning in the CI/CD pipeline to detect unexpected base image changes.

Generated by OpenCVE AI on September 9, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-sdk-builder. The software uses a flexible label, called a mutable tag, to identify its base container image instead of a unique, fixed identifier. This practice allows the underlying base image to change unexpectedly between builds. Such a change could introduce vulnerabilities or malicious code into the build process, posing a supply chain integrity risk.
Title operator-sdk-builder: operator-sdk-builder: Base image referenced by mutable tag rather than sha256 digest
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87055 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere