Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41888

Опубликовано: 14 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2//manifests/ endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

A flaw was found in Distribution, a software toolkit used for managing container content. This vulnerability allows a remote attacker to bypass security settings designed to prevent the deletion of container tags. By sending a specific request, an attacker can remove tags from repositories even when the system administrator has explicitly disabled this function. This unauthorized action could lead to the removal of critical container references, potentially causing disruption or denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift3/ose-operator-lifecycle-managerFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-framework-tools-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-lifecycle-managerFix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-lifecycle-manager-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-operator-registryFix deferred
Red Hat OpenShift Container Platform 4redhat/redhat-operator-indexFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-15
https://bugzilla.redhat.com/show_bug.cgi?id=2477528github.com/distribution/distribution: Distribution: Security bypass allows unauthorized tag deletion

EPSS

Процентиль: 22%
0.00294
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
nvd
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS3: 6.5
debian
3 месяца назад

Distribution is a toolkit to pack, ship, store, and deliver container ...

github
3 месяца назад

Distribution's tag deletion bypasses `storage.delete.enabled` configuration

CVSS3: 6.5
fstec
3 месяца назад

Уязвимость инструментария для хранения и доставки содержимого контейнеров Distribution, связанная с недостатками механизма авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 22%
0.00294
Низкий

6.5 Medium

CVSS3