Central Dogma Git mirror trusts any SSH host key
A disclosed flaw in LINE's configuration store means every outbound git+ssh mirror connection accepts whatever server key it is offered, according to the advisory.
13 Sept 2026
Central Dogma's Git mirror SSH client (SshGitMirror) installs a server key verifier that unconditionally returns true and disables known_hosts fallbacks, so every outbound git+ssh:// mirror connection trusts any host key presented. An on-path attacker can impersonate the remote git server to exfiltrate mirrored configuration secrets or inject arbitrary commits that propagate to downstream services.
Disclosed 21 May 2026 · Record updated 13 September 2026
Allows a network-positioned attacker to intercept mirror SSH sessions, stealing mirrored repository contents (DB credentials, API keys, certificates) and mirror credentials, or serving malicious commits that Central Dogma broadcasts to all subscribing microservices, a supply-chain trust compromise.
A disclosed flaw in LINE's configuration store means every outbound git+ssh mirror connection accepts whatever server key it is offered, according to the advisory.
13 Sept 2026