CVE-2026-103868: Pulp-container: registry credentials are reused across remotes in a worker
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.
Other sources
RegistryAuthHttpDownloader.registryauth is a class attribute (pulpcontainer/app/downloaders.py). Every instance in the worker shares one basic-auth value and one bearer token. A later download in that process, including another remote, task, or domain, sends the Authorization header stored by an earlier authenticated sync. Remote username, password, and clientkey are write-only on the API, so the syncing account cannot read them back. The caller obtains them by pointing a remote they can sync at a server they control. Introduced in dbef26e7, first release 1.3.0. This is a separate CVE from the pulp-ansible token cache: different repository, independently fixable.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs permission to sync a container remote and must be able to configure that remote to use a server they control. They do not need to read stored remote credentials through the API.
What credentials may be exposed?
A controlled registry server can receive a username and password used for basic authentication, or a bearer token, that was retained from an earlier authenticated sync in the same worker process. The exposed credential may then be reusable against its upstream registry.
Does the exposure stay within one remote or domain?
No. A later download in the same worker can send credentials retained from an earlier sync, including downloads for another remote, task, or domain.
Are releases before 1.3.0 affected?
The flaw was introduced by dbef26e7 and first appeared in release 1.3.0. No fixed release is identified in the provided information.
Does exploitation alter stored content or interrupt service?
No. The provided information states that content stored in Pulp is not changed and the service is not stopped.