← Back

CVE-2026-28909

nvd nist
Published: Apr 30, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Affected (1)

Products: Apple: Container
1 product
Container
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.12.3

References (1)

Timeline

No history available yet.