Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-41888

Опубликовано: 14 мая 2026
Источник: debian

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
docker-registryunfixedpackage
docker-registryno-dsatrixiepackage

Примечания

  • https://github.com/distribution/distribution/security/advisories/GHSA-6pjf-3r9x-m592

  • https://github.com/distribution/distribution/commit/8baf3e08266a19590cc5d4725f3976a9a876d4bf (v3.1.1)

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
redhat
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
nvd
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

github
3 месяца назад

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с недостатками механизма авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации