PT-2026-36209 · Unknown · Containers

·

CVE-2026-28909

·

Published

2026-04-30

·

Updated

2026-05-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions container versions prior to 0.12.3
Description Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext.
Recommendations Update to version 0.12.3.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28909
GHSA-M5RP-XCPF-R8M7

Affected Products

Containers