THREAT OPS › Threat News › [GHSA] GHSA-vjfw-cpmh-xwv3 (high) — Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
[GHSA] GHSA-vjfw-cpmh-xwv3 (high) — Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
GHSA-vjfw-cpmh-xwv3 Severity: high CVE: CVE-2026-11745
Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)
# Vulnerability
Central Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally for every outbound SSH connection used by `git+ssh://` mirrors. The accompanying lines disable the `known
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-11745cve
Original source: https://github.com/advisories/GHSA-vjfw-cpmh-xwv3