THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vjfw-cpmh-xwv3 (high) — Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

[GHSA] GHSA-vjfw-cpmh-xwv3 (high) — Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

medgithub_advisoriesPublished 2026-09-11

GHSA-vjfw-cpmh-xwv3 Severity: high CVE: CVE-2026-11745

Central Dogma: SSH host-key verification permanently disabled in Git mirror (SshGitMirror)

# Vulnerability

Central Dogma's Git mirror SSH client installs an Apache MINA SSHD `ServerKeyVerifier` lambda that returns `true` unconditionally for every outbound SSH connection used by `git+ssh://` mirrors. The accompanying lines disable the `known

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vjfw-cpmh-xwv3