REDHAT-BUG-2544601: Medium severity Pulp Pulp Container Plugin vulnerability

Published Oct 1, 2026
·
Updated

RegistryAuthHttpDownloader.registryauth is a class attribute (pulpcontainer/app/downloaders.py). Every instance in the worker shares one basic-auth value and one bearer token. A later download in that process, including another remote, task, or domain, sends the Authorization header stored by an earlier authenticated sync. Remote username, password, and clientkey are write-only on the API, so the syncing account cannot read them back. The caller obtains them by pointing a remote they can sync at a server they control. Introduced in dbef26e7, first release 1.3.0. This is a separate CVE from the pulp-ansible token cache: different repository, independently fixable.

Affected Software

1 affected component
Pulp Pulp Container Plugin>=1.3.0

Event History

Oct 1, 2026
Data Sourced
via Red Hat·11:53 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What deployment scope can be affected by the shared authentication state?

Authentication state is shared by every RegistryAuthHttpDownloader instance within a worker process. A later download can therefore use credentials or a bearer token from an earlier authenticated sync, including across different remotes, tasks, or domains handled by that process.

2

What access would an attacker need to obtain leaked credentials?

The attacker needs to be able to point a remote they can sync at a server they control. They can then obtain the Authorization header sent by a later download that reuses authentication state from an earlier authenticated sync in the same worker.

3

Does the API's write-only handling of remote secrets prevent disclosure?

No. Remote usernames, passwords, and client keys cannot be read back through the API, but the issue can expose the resulting basic-auth value or bearer token through an outbound Authorization header.

4

Which releases are identified as affected?

The issue was introduced in commit dbef26e7 and was first released in version 1.3.0. The provided data does not identify a fixed version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203