CVE-2026-24845: malcontent's OCI image scanning could expose registry credentials
Malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. Malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a WWW-Authenticate header redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint.
Fix: Default to anonymous auth for OCI pulls
Acknowledgements
Thank you to Oleh Konko from 1seal for discovering and reporting this issue.
Other sources
malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a WWW-Authenticate header redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint. Version 1.20.3 fixes the issue by defaulting to anonymous auth for OCI pulls.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24845?
CVE-2026-24845 has a high severity due to the potential exposure of sensitive Docker registry credentials.
How do I fix CVE-2026-24845?
You can fix CVE-2026-24845 by updating malcontent to version 1.20.3 or later.
What software is affected by CVE-2026-24845?
CVE-2026-24845 affects malcontent versions between 0.10.0 and 1.20.3, as well as google/go-containerregistry versions prior to 1.20.3.
What are the potential consequences of CVE-2026-24845?
The potential consequences of CVE-2026-24845 include unauthorized access to Docker registry credentials, leading to data breaches.
Is there a workaround for CVE-2026-24845?
Currently, the best mitigation for CVE-2026-24845 is to upgrade to the corrected versions of the affected software.