Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41888

Опубликовано: 14 мая 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:*
Версия до 3.1.1 (исключая)

EPSS

Процентиль: 22%
0.00294
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
redhat
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
debian
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

github
3 месяца назад

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с недостатками механизма авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.00294
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-863