Description
A flaw was found in olm-operator-konflux-sample. The hermetic build mode is disabled by default, allowing bundle builds to perform live network fetches. This means that external, unverified resources can be pulled during the build process, potentially compromising the integrity and trustworthiness of the resulting software artifacts. This introduces a supply chain risk where the final product might contain unintended or malicious code.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Supply Chain Compromise via untrusted network fetches in bundle builds
Action: Assess Impact
AI Analysis

Impact

The flaw allows bundle builds to download external, unverified resources because the hermetic build mode is disabled by default. This means that during a build, code or artifacts that have not been vetted by the developer can be incorporated into the final product, potentially introducing malicious or unintended content. The weakness is a lack of restriction on external fetches, which can compromise the integrity and trustworthiness of software artifacts.

Affected Systems

The vulnerability affects the olm-operator-konflux-sample project. No specific version information is provided, so all current versions of this component are potentially impacted until a patch or configuration change is applied.

Risk and Exploitability

The CVSS score of 2.6 indicates a low overall severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not widely exploited at present. The attack vector is inferred to be an attacker who can influence the build configuration or supply untrusted resources to the build environment. By manipulating the sources used during the build, an adversary could inject malicious code into the resulting artifacts, creating a supply chain risk for downstream users.

Generated by OpenCVE AI on September 9, 2026 at 06:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure build processes to enable hermetic mode, preventing the bundle build from fetching external resources
  • Verify and whitelist all external dependencies used in bundle builds, ensuring they come from trusted, signed sources
  • Contact the olm-operator-konflux-sample maintainers to obtain or apply any available fix or patch
  • Implement build isolation, such as using containerized or offline build environments, to mitigate the impact of untrusted network access

Generated by OpenCVE AI on September 9, 2026 at 06:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in olm-operator-konflux-sample. The hermetic build mode is disabled by default, allowing bundle builds to perform live network fetches. This means that external, unverified resources can be pulled during the build process, potentially compromising the integrity and trustworthiness of the resulting software artifacts. This introduces a supply chain risk where the final product might contain unintended or malicious code.
Title olm-operator-konflux-sample: olm-operator-konflux-sample: Hermetic build disabled by default; bundle build performs live network fetches
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87058 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere