#VU125340 Improper access control in distribution - CVE-2026-35172

 

#VU125340 Improper access control in distribution - CVE-2026-35172

Published: April 8, 2026


Vulnerability identifier: #VU125340
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-35172
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
distribution
Software vendor:
Docker Inc.

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the repository-scoped redis blob descriptor cache invalidation logic when handling blob delete and subsequent stat or get operations across repositories. A remote attacker can request the same digest from another repository that still references it to disclose sensitive information.

Only deployments with both redis blob descriptor caching and delete enabled are vulnerable.


Remediation

Install security update from vendor's website.

External links