Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qvqc-4c52-x6qp | regclient may leak authentication credentials to external blob stores |
Wed, 12 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue. | |
| Title | regclient may leak authentication credentials to external blob stores | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T14:35:58.638Z
Reserved: 2026-05-29T14:35:45.903Z
Link: CVE-2026-49349
Updated: 2026-08-12T14:35:55.138Z
Status : Received
Published: 2026-08-12T15:17:37.507
Modified: 2026-08-12T15:17:37.507
Link: CVE-2026-49349
No data.
OpenCVE Enrichment
No data.
-
CWE-522
Insufficiently Protected Credentials
Github GHSA