CRITICAL 9.3
GHSA-8g5p-jxp9-457c
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
Quick fix
GHSA-8g5p-jxp9-457c — github.com/kubev2v/assisted-migration-agent: upgrade to the fixed version with the command below.
go get github.com/kubev2v/assisted-migration-agent@v0.16.0 Details
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/kubev2v/assisted-migration-agent
Introduced in:
0 Fixed in: 0.16.0 Fix
go get github.com/kubev2v/assisted-migration-agent@v0.16.0 References
- https://nvd.nist.gov/vuln/detail/CVE-2026-53475 [ADVISORY]
- https://github.com/kubev2v/assisted-migration-agent/pull/268 [WEB]
- https://github.com/kubev2v/assisted-migration-agent/commit/b940fec9f5032a0801e994054d30e81d64b2942a [WEB]
- https://access.redhat.com/security/cve/CVE-2026-53475 [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2487232 [WEB]
- https://github.com/kubev2v/assisted-migration-agent [PACKAGE]