{"id":"GHSA-vjfw-cpmh-xwv3","summary":"Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)","details":"# Vulnerability\n\nCentral Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally for every outbound SSH connection used by `git+ssh://` mirrors. The accompanying lines disable the `known_hosts` and `~/.ssh/config` fallbacks, and a repo-wide search confirms that no host-key pinning mechanism (no `acceptedHostKeys`, `knownHosts`, `KnownHostsServerKeyVerifier`, `StaticServerKeyVerifier`, or `RequiredServerKeyVerifier`) exists anywhere in `server-mirror-git/`. Operators have no opt-in way to enable verification. Every outbound mirror connection blindly trusts whatever host key the remote presents.\n\n## Evidence\n\nFile: `server-mirror-git/src/main/java/com/linecorp/centraldogma/server/internal/mirror/SshGitMirror.java`\nLines 143-160 (especially 149) on branch `main` @ commit `d64a5151`:\n\n```java\nprivate SshClient createSshClient() {\n    final ClientBuilder builder = ClientBuilder.builder();\n    // Do not use local file system.\n    builder.hostConfigEntryResolver(HostConfigEntryResolver.EMPTY);   // line 146\n    builder.fileSystemFactory(NoneFileSystemFactory.INSTANCE);        // line 147\n    // Do not verify the server key.\n    builder.serverKeyVerifier((clientSession, remoteAddress, serverKey) -\u003e true);  // line 149\n    ...\n}\n```\n\nVerification:\n\n- Read confirmed on 2026-05-21 against `main` @ `d64a5151`.\n- A multi-agent code audit verified that no operator-facing pinning field exists on `SshKeyCredential`, `PasswordCredential`, or `MirrorContext`.\n- Exploit PoC reproduced locally with a `paramiko`-based fake SSH server bound to 127.0.0.1. The fake server presents an ephemeral RSA host key never seen before; the Central Dogma mirror client accepts the connection and proceeds to authentication, logging the offered username and public-key fingerprint. A correctly hardened SSH client would refuse the connection before reaching the authentication phase.\n- Full PoC artifacts (read-only, loopback-only) at `~/centraldogma-poc/C1_ssh_hostkey_bypass/` on the reporter's workstation.\n\n## Impact\n\nThreat model: An on-path attacker on the corporate network — ARP spoofing on the LAN, internal DNS poisoning, malicious internal DNS overriding `github.com` or the configured internal git hostname, BGP hijack, sidecar/CNI compromise in Kubernetes, or any process able to answer TCP on the resolved IP. No Central Dogma account required; only network position.\n\n1. **Direction `LOCAL_TO_REMOTE`**: the attacker impersonating the remote git server receives the entire mirrored repository contents over the SSH session. Central Dogma is a configuration store, so this typically exfiltrates DB credentials, third-party API keys, certificates, feature flags, and any other secret configuration committed to mirrored repositories.\n2. **Direction `REMOTE_TO_LOCAL`**: the attacker can serve arbitrary commits which Central Dogma materializes into the local repo and then broadcasts to every subscribing microservice via the watch API. This is a supply-chain root-of-trust compromise across all downstream services consuming Central Dogma configuration.\n3. **Credential theft chain with finding H2** (mirror credentials are not bound to a hostname): an SSH key or access token configured for `github.com` can be captured by the attacker's fake server and replayed against the real upstream, extending impact beyond Central Dogma itself.\n\nScope is `Changed` (CVSS) because exploitation alters trust assumptions of every downstream client of Central Dogma, not just Central Dogma itself.\n\n## How to fix\n\n1. Add an `acceptedHostKeys: List\u003cString\u003e` field to `SshKeyCredential` and `PasswordCredential` (or to `MirrorContext`). Values are SHA-256 fingerprints of trusted remote SSH server host keys, e.g. `SHA256:nThbg6kXUpJWGl7E1IGOCspRomTxdCARLviKw6E5SY8`.\n2. Replace the accept-all lambda at `SshGitMirror.java:149` with a verifier that computes the SHA-256 fingerprint of the presented host key and compares it against the credential's allowlist using a constant-time comparison.\n3. Refuse to connect when `acceptedHostKeys` is empty — fail-closed. Do not implement implicit TOFU.\n4. Optionally provide an admin-only `dogma mirror probe-host-key \u003cremote\u003e` tool that performs a single audited connection, prints the server's fingerprint, and prompts the operator to add it to the credential. This makes TOFU an explicit, audited operation.\n5. Update `SshGitMirrorTest.java` and `it/mirror/*` tests to pin a test fingerprint or use the explicit trust-once tool, so the regression cannot silently return.","aliases":["CVE-2026-11745"],"modified":"2026-09-11T21:00:06.354959044Z","published":"2026-09-11T20:45:50Z","database_specific":{"nvd_published_at":"2026-06-22T03:16:42Z","cwe_ids":["CWE-322"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-11T20:45:50Z"},"references":[{"type":"WEB","url":"https://github.com/line/centraldogma/security/advisories/GHSA-vjfw-cpmh-xwv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11745"},{"type":"PACKAGE","url":"https://github.com/line/centraldogma"}],"affected":[{"package":{"name":"com.linecorp.centraldogma:centraldogma-server-mirror-git","ecosystem":"Maven","purl":"pkg:maven/com.linecorp.centraldogma/centraldogma-server-mirror-git"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.84.0"}]}],"versions":["0.62.0","0.62.1","0.63.0","0.63.1","0.63.2","0.63.3","0.64.0","0.64.1","0.64.2","0.64.3","0.65.0","0.65.1","0.66.0","0.66.1","0.67.0","0.67.1","0.67.2","0.67.3","0.68.0","0.69.0","0.69.1","0.70.0","0.71.0","0.72.0","0.73.0","0.73.1","0.74.0","0.75.0","0.75.1","0.76.0","0.77.0","0.77.1","0.77.2","0.77.3","0.77.4","0.78.0","0.78.1","0.79.0","0.79.1","0.79.2","0.80.0","0.81.0","0.82.0","0.83.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vjfw-cpmh-xwv3/GHSA-vjfw-cpmh-xwv3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:L"}]}