GPU VulnDB

Database/Container, Kubernetes & orchestration

doco-cd: artifact-supplied config can turn off its own signature verification, bypassing OCI trust policy

CVSS 6.5CVE-2026-54248Container, Kubernetes & orchestrationcurated

Impact

doco-cd reads deployment config out of the OCI artifact it is about to verify, so an attacker who can push to the watched OCI tag can ship an unsigned artifact whose embedded .doco-cd.yml sets oci.verify: false and have verification skipped entirely. The signature gate that the operator thought was enforced globally via OCI_TRUST_POLICY stops applying, and untrusted Compose/Swarm content is deployed. For anyone using doco-cd to roll out workloads onto a fleet, this is a supply-chain path from registry write access to arbitrary container deployment on the hosts the controller manages - the blast radius is whatever those hosts run. It only bites deployments that source config from artifact contents, such as poll or webhook flows without trusted inline overrides.

Who can reach it

Requires write/push access to the OCI repository or tag that doco-cd polls - a CI token, a compromised registry credential, or any account with push rights. No access to the doco-cd host itself is needed; the controller pulls the poisoned artifact on its own schedule or on a webhook.

What to do

Upgrade to doco-cd 0.90.1, which treats artifact-contained .doco-cd.yml as untrusted for trust-policy decisions and refuses to downgrade verification when OCI_TRUST_POLICY.enabled is true; this is a controller restart, no node disruption. Until then the maintainers' workarounds apply: do not source deployment config from untrusted artifact contents, use trusted inline POLL_CONFIG.deployments, restrict push permissions on the watched repositories and tags, pin immutable digests, and watch for unexpected digest changes or failed verification events.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.