Description
The mirror-registry doesn't properly sanitize the host header HTTP header in HTTP request received, allowing an attacker to perform malicious redirects to attacker-controlled domains or phishing campaigns.
Product status
Timeline
2025-07-21: | Reported to Red Hat. |
2025-07-21: | Made public. |
Credits
Red Hat would like to thank Antony Di Scala and Michael Whale for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-7777
bugzilla.redhat.com/show_bug.cgi?id=2382545 (RHBZ#2382545)