A new CVE (CVE-2026-4740) has been reported that affects the registration controller:
https://access.redhat.com/security/cve/cve-2026-4740We have implemented fixes and merged them into the main branch, as well as the release-1.0, release-1.1, and release-1.2 branches.
For reference, please see the main branch PR:
https://github.com/open-cluster-management-io/ocm/pull/1476We plan to publish new releases (v1.2.1, v1.1.2, and v1.0.1) later this week.
We will share another update once the releases are available.
Regards,
Mike Ng
Open Cluster Management Maintainer