PT-2026-80338 · Go · Github.Com/Distribution/Distribution+1

Published

2026-08-18

·

Updated

2026-08-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In github.com/distribution/distribution and github.com/distribution/distribution/v3 before 3.1.0, when storage.cache.blobdescriptor is configured with redis and storage.delete.enabled is true, deleting a blob in one repository clears the shared digest descriptor in Redis but leaves stale repository-scoped membership behind. If another repository subsequently requests or stats the same digest, the shared descriptor is repopulated and the deleted blob becomes accessible again in the first repository.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GO-2026-4942

Affected Products

Github.Com/Distribution/Distribution
Github.Com/Distribution/Distribution/V3