Database/Container, Kubernetes & orchestration
doco-cd: artifact-supplied config can turn off its own signature verification, bypassing OCI trust policy
Impact
doco-cd reads deployment config out of the OCI artifact it is about to verify, so an attacker who can push to the watched OCI tag can ship an unsigned artifact whose embedded .doco-cd.yml sets oci.verify: false and have verification skipped entirely. The signature gate that the operator thought was enforced globally via OCI_TRUST_POLICY stops applying, and untrusted Compose/Swarm content is deployed. For anyone using doco-cd to roll out workloads onto a fleet, this is a supply-chain path from registry write access to arbitrary container deployment on the hosts the controller manages - the blast radius is whatever those hosts run. It only bites deployments that source config from artifact contents, such as poll or webhook flows without trusted inline overrides.
Who can reach it
Requires write/push access to the OCI repository or tag that doco-cd polls - a CI token, a compromised registry credential, or any account with push rights. No access to the doco-cd host itself is needed; the controller pulls the poisoned artifact on its own schedule or on a webhook.
What to do
Upgrade to doco-cd 0.90.1, which treats artifact-contained .doco-cd.yml as untrusted for trust-policy decisions and refuses to downgrade verification when OCI_TRUST_POLICY.enabled is true; this is a controller restart, no node disruption. Until then the maintainers' workarounds apply: do not source deployment config from untrusted artifact contents, use trusted inline POLL_CONFIG.deployments, restrict push permissions on the watched repositories and tags, pin immutable digests, and watch for unexpected digest changes or failed verification events.
References
Related entries
- KubeEdge CloudHub: unvalidated 32-bit payload length lets an edge peer exhaust control-plane memoryCVE-2026-62370 · KubeEdge CloudHub viaduct packer (PackageHeader.PayloadLen)Medium
- Submariner: IPsec pre-shared key stored unencrypted in the Submariner custom resourceCVE-2026-66781 · Submariner operator (Submariner CR, IPsec pre-shared key)Medium
- KubeSphere cluster-controller: Cluster CRD endpoint is fetched unvalidated, giving SSRF from the controller podCVE-2026-71208 · KubeSphere cluster-controller (Cluster CRD connection config, addCluster / Discovery.ServerVersion)Medium
- ECK operator: unvalidated secret reference lets a namespace-scoped user read secrets from any namespaceCVE-2026-72640 · Elastic Cloud on Kubernetes (ECK) operator (secret reference reconciliation)Medium
- Elastic Cloud on Kubernetes: Fleet Server Elasticsearch token written into the workload spec in cleartextCVE-2026-72648 · Elastic Cloud on Kubernetes (ECK) operator - Fleet Server workload specMedium
- Dokploy: compose service names are interpolated into shell commands, giving command execution on the Docker hostCVE-2026-72739 · Dokploy (compose deployment createCommand shell interpolation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.