Executive brief
A vulnerability in the Red Hat OpenShift Mirror Registry allows unauthorized individuals to identify valid user accounts and email addresses. By observing differences in error messages during login attempts or account creation, an attacker can map out the organization's user list. This information can be used to facilitate more targeted social engineering or password-guessing attacks against the infrastructure.
Technical details
A flaw exists in the OpenShift Mirror Registry (specifically affecting versions 1 and 2.0) where the application returns distinct error messages depending on whether a username or email address already exists in the system. This is classified as a CWE-209 (Generation of Error Message Containing Sensitive Information) vulnerability. An unauthenticated, remote attacker can exploit this behavior by submitting various authentication requests or account creation attempts and analyzing the server's responses. This allows for the enumeration of valid user identifiers, which can serve as a precursor to brute-force or phishing campaigns. Red Hat has acknowledged the issue in the mirror-registry-rhel8 package.
Affected products
- Red Hat mirror registry for Red Hat OpenShift 1, 2.0
Timeline
- 2026-04-08: disclosed: Initial disclosure by Red Hat
- 2026-04-08: advisory: NVD publication date