Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2026-35172

Medium priority
Needs evaluation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis...

1 affected package

docker-registry

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker-registry Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33540

Medium priority
Needs evaluation

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by...

1 affected package

docker-registry

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker-registry Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-2253

Medium priority

Some fixes available 5 of 6

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an...

1 affected package

docker-registry

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker-registry Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-41190

Low priority

Some fixes available 11 of 20

The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to...

3 affected packages

containerd, docker-registry, docker.io

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
docker-registry Not affected Not affected Not affected Not affected
docker.io Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-11468

Low priority

Some fixes available 1 of 3

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.

1 affected package

docker-registry

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker-registry Not affected Not affected Not affected
Show less packages