Improper access control in distribution - CVE-2026-35172
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the repository-scoped redis blob descriptor cache invalidation logic when handling blob delete and subsequent stat or get operations across repositories. A remote attacker can request the same digest from another repository that still references it to disclose sensitive information.
Only deployments with both redis blob descriptor caching and delete enabled are vulnerable.
Affected software
Fedora
docker-distribution
Red Hat OpenShift Container Platform
How to mitigate CVE-2026-35172
docker-distribution - update to 3.1.1-1.fc45
Red Hat OpenShift Container Platform - addressed in versions 4.12.92, 4.15.65