Boletines de Vulnerabilidades |
CVE-2026-49349 |
|
| Software afectado | DOCKER |
| regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-49349 | |






