Trust-Boundary Flaw in Doco-CD Affects Docker Compose Deployment
CVE-2026-54248

6.5MEDIUM

Key Information:

Vendor

Kimdre

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-54248?

Doco-CD, a GitOps continuous delivery tool, is affected by a trust-boundary flaw that compromises OCI artifact verification processes. Before version 0.90.1, attackers with write access to specific OCI tags could exploit this vulnerability by publishing unsigned or improperly signed artifacts containing a .doco-cd.yml file with directive oci.verify: false. This situation enabled a bypass of signature verification, allowing untrusted deployment content to be applied. Users deploying from OCI artifacts where deployment configuration is sourced directly from artifact contents are particularly at risk. Mitigation strategies include avoiding the use of untrusted OCI contents for deployment configuration, employing trusted inline deployment settings, and restricting write access to the associated OCI repositories. Additionally, using immutable digest pinning and closely monitoring artifact digest changes can help maintain security integrity.

Affected Version(s)

doco-cd < 0.90.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.