CVE-2026-28909: Medium severity container vulnerability
Published Apr 30, 2026
·Updated
Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
Affected Software
2 affected components
container<0.12.3
Apple Container Swift<0.12.3
Event History
Apr 30, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28909?
CVE-2026-28909 is considered a critical vulnerability due to the exposure of registry credentials in plaintext.
2
How do I fix CVE-2026-28909?
To fix CVE-2026-28909, upgrade the container to version 0.12.3 or later.
3
What systems are affected by CVE-2026-28909?
CVE-2026-28909 affects all versions of the container prior to version 0.12.3.
4
What are the consequences of CVE-2026-28909?
The primary consequence of CVE-2026-28909 is the potential exposure of users' registry credentials to attackers.
5
How can I identify if I am vulnerable to CVE-2026-28909?
You can identify vulnerability to CVE-2026-28909 by checking if you are using a container version earlier than 0.12.3.