PT-2026-53024 · Regclient · Regclient

CVE-2026-49349

·

Published

2026-06-26

·

Updated

2026-08-12

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions regclient (affected versions not specified)
Description Authentication credentials for a registry may be leaked to external servers. This occurs when a malicious registry server, a malicious blob store, or a registry that fails to restrict external URLs for foreign blobs is used. If an OCI image manifest contains a layer descriptor with a urls field pointing to an attacker-controlled host, and the primary blob request to the registry fails, the software falls back to these external URLs. If the external server requests authentication, the credentials for the original registry server are sent to the attacker.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49349
GHSA-QVQC-4C52-X6QP
GO-2026-5822
OPENSUSE-SU-2026:21483-1

Affected Products

Regclient