CVE-2026-65388: Containerization vulnerability
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
containerizationto a version that resolves this vulnerability.Fixed in 0.41.0
Event History
Frequently Asked Questions
What must an attacker control to exploit this issue?
The attacker must control a container registry. They may then direct a client's token request to an attacker-chosen host and receive the victim's registry credentials.
Which versions are affected?
The issue is addressed in containerization version 0.41.0. The provided information does not specify the first affected version or whether versions after 0.41.0 are affected.
What is the immediate remediation?
Update containerization to version 0.41.0, which addresses the vulnerability.