Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Maven
Not in CISA KEV

CVE-2026-11745 centraldogma-server-mirro…

CVE-2026-11745 is a CWE-322 vulnerability in com.linecorp.centraldogma:centraldogma-server-mirror-git. A fix is available for com.linecorp.centraldogma:centraldogma-server-mirror-git — see the affected versions and patch details below.

Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

Published
Sep 11, 2026
Updated
Sep 11, 2026
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Sep 17, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • A successful exploit gives an attacker total control of the affected component, not partial access.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-11745.

EPSS Exploitation Probability

via FIRST.org ↗
0.2%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs13th percentile — riskier than 13% of all scored CVEsHighest risk

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Real-World Exposure

1 pkg affected
com.linecorp.centraldogma:centraldogma-server-mirror-git

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

Vulnerability

Central Dogma's Git mirror SSH client installs an Apache MINA SSHD ServerKeyVerifier lambda that returns true unconditionally for every outbound SSH connection used by git+ssh:// mirrors. The accompanying lines disable the known_hosts and ~/.ssh/config fallbacks, and a repo-wide search confirms that no host-key pinning mechanism (no acceptedHostKeys, knownHosts, KnownHostsServerKeyVerifier, StaticServerKeyVerifier, or RequiredServerKeyVerifier) exists anywhere in server-mirror-git/. Operators have no opt-in way to enable verification. Every outbound mirror connection blindly trusts whatever host key the remote presents.

Evidence

File: server-mirror-git/src/main/java/com/linecorp/centraldogma/server/internal/mirror/SshGitMirror.java Lines 143-160 (especially 149) on branch main @ commit d64a5151:

private SshClient createSshClient() {
    final ClientBuilder builder = ClientBuilder.builder();
    // Do not use local file system.
    builder.hostConfigEntryResolver(HostConfigEntryResolver.EMPTY);   // line 146
    builder.fileSystemFactory(NoneFileSystemFactory.INSTANCE);        // line 147
    // Do not verify the server key.
    builder.serverKeyVerifier((clientSession, remoteAddress, serverKey) -> true);  // line 149
    ...
}

Verification:

  • Read confirmed on 2026-05-21 against main @ d64a5151.
  • A multi-agent code audit verified that no operator-facing pinning field exists on SshKeyCredential, PasswordCredential, or MirrorContext.
  • Exploit PoC reproduced locally with a paramiko-based fake SSH server bound to 127.0.0.1. The fake server presents an ephemeral RSA host key never seen before; the Central Dogma mirror client accepts the connection and proceeds to authentication, logging the offered username and public-key fingerprint. A correctly hardened SSH client would refuse the connection before reaching the authentication phase.
  • Full PoC artifacts (read-only, loopback-only) at ~/centraldogma-poc/C1_ssh_hostkey_bypass/ on the reporter's workstation.

Impact

Threat model: An on-path attacker on the corporate network — ARP spoofing on the LAN, internal DNS poisoning, malicious internal DNS overriding github.com or the configured internal git hostname, BGP hijack, sidecar/CNI compromise in Kubernetes, or any process able to answer TCP on the resolved IP. No Central Dogma account required; only network position.

  1. Direction LOCAL_TO_REMOTE: the attacker impersonating the remote git server receives the entire mirrored repository contents over the SSH session. Central Dogma is a configuration store, so this typically exfiltrates DB credentials, third-party API keys, certificates, feature flags, and any other secret configuration committed to mirrored repositories.
  2. Direction REMOTE_TO_LOCAL: the attacker can serve arbitrary commits which Central Dogma materializes into the local repo and then broadcasts to every subscribing microservice via the watch API. This is a supply-chain root-of-trust compromise across all downstream services consuming Central Dogma configuration.
  3. Credential theft chain with finding H2 (mirror credentials are not bound to a hostname): an SSH key or access token configured for github.com can be captured by the attacker's fake server and replayed against the real upstream, extending impact beyond Central Dogma itself.

Scope is Changed (CVSS) because exploitation alters trust assumptions of every downstream client of Central Dogma, not just Central Dogma itself.

How to fix

  1. Add an acceptedHostKeys: List<String> field to SshKeyCredential and PasswordCredential (or to MirrorContext). Values are SHA-256 fingerprints of trusted remote SSH server host keys, e.g. SHA256:nThbg6kXUpJWGl7E1IGOCspRomTxdCARLviKw6E5SY8.
  2. Replace the accept-all lambda at SshGitMirror.java:149 with a verifier that computes the SHA-256 fingerprint of the presented host key and compares it against the credential's allowlist using a constant-time comparison.
  3. Refuse to connect when acceptedHostKeys is empty — fail-closed. Do not implement implicit TOFU.
  4. Optionally provide an admin-only dogma mirror probe-host-key <remote> tool that performs a single audited connection, prints the server's fingerprint, and prompts the operator to add it to the credential. This makes TOFU an explicit, audited operation.
  5. Update SshGitMirrorTest.java and it/mirror/* tests to pin a test fingerprint or use the explicit trust-once tool, so the regression cannot silently return.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
Mavencom.linecorp.centraldogma:centraldogma-server-mirror-gitall versions0.84.0com.linecorp.centraldogma:centraldogma-server-mirror-git:0.84.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for com.linecorp.centraldogma:centraldogma-server-mirror-git, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update com.linecorp.centraldogma:centraldogma-server-mirror-git to 0.84.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-11745 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2026-11745 can be triaged on real exposure rather than presence alone.

Tailored to CVE-2026-11745. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

# Vulnerability Central Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally for every outbound SSH connection used by `git+ssh://` mirrors. The accompanying lines disable the `known_hosts` and `~/.ssh/config` fallbacks, and a repo-wide search confirms that no host-key pinning mechanism (no `acceptedHostKeys`, `knownHosts`, `KnownHostsServerKeyVerifier`, `StaticServerKeyVerifier`, or `RequiredServerKeyVerifier`) exists anywhere in `server-mirror-git/`. Operators have no opt-in way to enable verification. Every outbound mirro
O3 Security · Impact-Aware SCA

Is CVE-2026-11745 in your dependencies?

O3 Security finds CVE-2026-11745 across Maven dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.

CVE-2026-11745: centraldogma-server-mirro… | O3 Security