CVE-2026-87055

low Red Hat
CVSS v3 Base Score
2.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Confidentiality
Low
Integrity
None
Availability
None
Published: September 8, 2026 (2 days ago)
Last Modified: September 8, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in operator-sdk-builder. The software uses a flexible label, called a mutable tag, to identify its base container image instead of a unique, fixed identifier. This practice allows the underlying base image to change unexpectedly between builds. Such a change could introduce vulnerabilities or malicious code into the build process, posing a supply chain integrity risk.

CWE

CWE-829

References