Man-in-the-Middle Vulnerability in CentralDogma Server by LINE
CVE-2026-11745

8.8HIGH

Key Information:

Vendor
CVE Published:
22 June 2026

What is CVE-2026-11745?

A vulnerability exists in the CentralDogma Server where the Git mirror SSH client fails to verify host keys for git+ssh:// connections. This oversight allows an attacker to intercept communications during a connection, making it feasible for them to execute man-in-the-middle attacks, potentially leading to the compromise of mirrored repositories. Users running versions prior to 0.84.0 should take appropriate security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Central Dogma 0.84.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.