Improper access control in distribution - CVE-2026-35172

 

Improper access control in distribution - CVE-2026-35172

Published: April 8, 2026


Vulnerability identifier: #VU125340
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-35172
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Docker Inc.
Affected software:
distribution

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the repository-scoped redis blob descriptor cache invalidation logic when handling blob delete and subsequent stat or get operations across repositories. A remote attacker can request the same digest from another repository that still references it to disclose sensitive information.

Only deployments with both redis blob descriptor caching and delete enabled are vulnerable.


How to mitigate CVE-2026-35172

Install security update from vendor's website.

Sources