Description
A flaw was found in olm-operator-konflux-sample. The bundle builder stage installs and upgrades Python packages using pip, a package installer, without verifying their versions or using hash verification. This allows a malicious or compromised package to be introduced into the build process undetected, potentially leading to a supply chain compromise where untrusted code is incorporated into software builds.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Supply Chain Compromise
Action: Immediate Patch
AI Analysis

Impact

The flaw in olm-operator-konflux-sample allows its bundle builder stage to install or upgrade Python packages using pip without pinning specific versions or verifying package hashes. This lack of version control and hash checking permits a malicious or compromised package to enter the build process unnoticed, potentially inserting untrusted code into the final software artifact and creating a supply‑chain vulnerability.

Affected Systems

The vulnerability affects the olm-operator-konflux-sample bundle builder used in operator deployments. No specific product version information is included in the advisory, so any release that uses the unpatched bundle builder stage is potentially impacted.

Risk and Exploitability

With a CVSS score of 2.6, the severity is low, but the risk remains because the compromise occurs at build time, allowing malicious code to be embedded into software distributed to customers. The attack vector likely requires the attacker to supply malicious Python packages to the build environment or manipulate the dependency sources, which can be achieved if the build environment or package registry is compromised. The EPSS score is not available, and the vulnerability is not listed as a known exploited vulnerability in CISA’s KEV catalog.

Generated by OpenCVE AI on September 9, 2026 at 07:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update olm‑operator‑konflux‑sample so that the bundle builder pins pip dependencies and enforces hash verification for all Python packages.
  • If a vendor patch addressing the dependency verification issue is available, apply it immediately.
  • Configure the build pipeline to validate that all third‑party packages are sourced from trusted registries and match pre‑computed checksums before they are accepted for installation.

Generated by OpenCVE AI on September 9, 2026 at 07:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in olm-operator-konflux-sample. The bundle builder stage installs and upgrades Python packages using pip, a package installer, without verifying their versions or using hash verification. This allows a malicious or compromised package to be introduced into the build process undetected, potentially leading to a supply chain compromise where untrusted code is incorporated into software builds.
Title olm-operator-konflux-sample: olm-operator-konflux-sample: Unpinned pip dependency installation in bundle builder stage
Weaknesses CWE-494
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87059 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:30:06Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check