CVE-2026-33467: Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity Bypass
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33467?
CVE-2026-33467 is classified as a high severity vulnerability due to the potential for package integrity bypass.
How do I fix CVE-2026-33467?
To fix CVE-2026-33467, upgrade to the latest version of Elastic Package Registry that has addressed the cryptographic signature verification issue.
What kind of attack does CVE-2026-33467 allow?
CVE-2026-33467 allows an attacker to potentially manipulate network traffic, leading to an integrity bypass of packages.
Which software is affected by CVE-2026-33467?
CVE-2026-33467 specifically affects the Elastic Package Registry.
What is the cause of CVE-2026-33467?
CVE-2026-33467 is caused by improper verification of cryptographic signatures.