Description
A flaw was found in operator-sdk-builder. The repository lacks automated dependency-update configurations for its git submodules, Containerfile base image, and Tekton bundle references. This absence prevents the automatic flagging of stale or vulnerable dependencies. Consequently, this could lead to the inclusion of known vulnerable components in the build process, increasing the risk of security exposures.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Potential inclusion of vulnerable components during build processes
Action: Apply Configuration
AI Analysis

Impact

A flaw was discovered in the tool used to build operator bundles: operator-sdk-builder lacks mechanisms for automatically updating its git submodules, base images in the Containerfile, and Tekton bundle references. This omission means that when a build is performed, any dependency that has become stale or vulnerable can be pulled in without the build operator being aware, thereby allowing a known insecure component to become part of the final operator bundle.

Affected Systems

All installations of operator-sdk-builder that are used to produce operator bundles and rely on external git submodules, a Containerfile, or Tekton bundle references are affected. The issue applies regardless of the target deployment environment or the cloud platform in which the operator will run.

Risk and Exploitability

The CVSS score of 2.6 indicates low severity. Based on the description, the likely attack vector is a supply‑chain compromise of a submodule, base image, or bundle reference, or a deliberate omission by a build operator. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying a low probability of automated exploitation. However, an attacker who succeeds in injecting a vulnerable component or who relies on an unpatched dependency could create an operator bundle that contains known security weaknesses, potentially leading to downstream exploitation once the operator is deployed.

Generated by OpenCVE AI on September 9, 2026 at 07:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure automatic dependency‑update mechanisms for git submodules, Containerfile base images, and Tekton bundle references using a dependency‑management tool such as Dependabot.
  • Schedule periodic scans of all dependencies used in the build process to detect known vulnerabilities early.
  • Manually review and update any components identified as vulnerable immediately before or during each build cycle.

Generated by OpenCVE AI on September 9, 2026 at 07:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-sdk-builder. The repository lacks automated dependency-update configurations for its git submodules, Containerfile base image, and Tekton bundle references. This absence prevents the automatic flagging of stale or vulnerable dependencies. Consequently, this could lead to the inclusion of known vulnerable components in the build process, increasing the risk of security exposures.
Title operator-sdk-builder: operator-sdk-builder: No automated dependency-update configuration for submodules or Containerfile
Weaknesses CWE-1104
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87056 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:30:06Z

Weaknesses
  • CWE-1104

    Use of Unmaintained Third Party Components