Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ly Corporation
Ly Corporation central Dogma |
|
| Vendors & Products |
Ly Corporation
Ly Corporation central Dogma |
Mon, 22 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Central Dogma Git Mirror SSH Host Key Verification Missing Allowing Man‑in‑the‑Middle |
Mon, 22 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Git Mirror SSH Host Key Verification Bypass Leading to Repository Compromise | |
| Weaknesses | CWE-295 |
Mon, 22 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-322 | |
| Metrics |
ssvc
|
Mon, 22 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Git Mirror SSH Host Key Verification Bypass Leading to Repository Compromise | |
| Weaknesses | CWE-295 |
Mon, 22 Jun 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories. | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: LY-Corporation
Published:
Updated: 2026-06-22T16:29:43.057Z
Reserved: 2026-06-09T06:46:10.431Z
Link: CVE-2026-11745
Updated: 2026-06-22T16:29:34.546Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:03:47Z