This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
There is no application-level workaround that fully eliminates this race condition without a code change. The following deployment-level measures reduce exposure in multi-tenant environments: - Avoid mTLS client certificates for git repositories: If tenant Repository resources do not supply client TLS certificates (httpConfig.tls.clientCertificate), the most sensitive data (client private key material) is absent from the global transport and cannot leak. - Avoid skipServerVerification: Do not set httpConfig.skipServerVerification: true on any Repository resource. This prevents a tenant's InsecureSkipVerify=true from propagating to other tenants' clones, which would otherwise allow an on-path attacker to serve malicious configuration.
Wed, 16 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates) and installs it into go-git's process-global client.Protocols map via gitclient.InstallProtocol("https", ...). Because the worker renders devices for multiple organizations concurrently from a shared goroutine pool, whichever tenant's repository configuration is written last wins for all in-flight git.Clone calls. This race condition can cause one tenant's TLS settings, including InsecureSkipVerify or mTLS client credentials, to leak into another tenant's git operations. | |
| Title | Flightctl: flightctl: package-global go-git https transport mutated per-repo -- cross-tenant tls-config bleed | |
| First Time appeared |
Redhat
Redhat acm Redhat edge Manager |
|
| Weaknesses | CWE-413 | |
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:edge_manager:1 |
|
| Vendors & Products |
Redhat
Redhat acm Redhat edge Manager |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-16T15:20:50.013Z
Reserved: 2026-09-16T14:27:41.693Z
Link: CVE-2026-92615
No data.
Status : Received
Published: 2026-09-16T16:17:23.513
Modified: 2026-09-16T16:17:23.513
Link: CVE-2026-92615
No data.
OpenCVE Enrichment
No data.