Beveiligingsadvies

CVE-2026-41888

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-14 16:53:37
Laatst bijgewerkt 2026-05-14 18:38:43
Toegewezen door GitHub_M
CVSS-score 6.3
Status PUBLISHED

Beschrijving

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.