Improper access control in distribution - CVE-2026-35172

 

Improper access control in distribution - CVE-2026-35172

Published: April 8, 2026


Vulnerability identifier: #VU125340
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35172
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the repository-scoped redis blob descriptor cache invalidation logic when handling blob delete and subsequent stat or get operations across repositories. A remote attacker can request the same digest from another repository that still references it to disclose sensitive information.

Only deployments with both redis blob descriptor caching and delete enabled are vulnerable.


Affected software

distribution
Fedora
docker-distribution
Red Hat OpenShift Container Platform

How to mitigate CVE-2026-35172

Install security update from vendor's website.

distribution - update to 3.1.0
docker-distribution - update to 3.1.1-1.fc45
Red Hat OpenShift Container Platform - addressed in versions 4.12.92, 4.15.65

External References

Related Security Bulletins