Back

MEDIUM

Crafted Git build source can bypass certain policy validation

Published Oct 5, 2026

Description

A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly.

Affected products

Remediation

Vendor solution

Issue only affect special cases when running builds with optional Build policies with specific Git source rules. Only the Git source rules based on the repository URL are affected.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Docker
Published Oct 5, 2026
Updated Oct 6, 2026
Reserved Sep 17, 2026
CISA Vulnrichment
Updated Oct 6, 2026
NVD
Status Awaiting Analysis
Modified Oct 6, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Docker
Published Oct 5, 2026
Updated Oct 6, 2026
Exploited since n/a
EUVD-2026-92787