Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qvqc-4c52-x6qp | regclient may leak authentication credentials to external blob stores |
Thu, 13 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Regclient
Regclient regclient |
|
| Vendors & Products |
Regclient
Regclient regclient |
Wed, 12 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue. | |
| Title | regclient may leak authentication credentials to external blob stores | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T14:35:58.638Z
Reserved: 2026-05-29T14:35:45.903Z
Link: CVE-2026-49349
Updated: 2026-08-12T14:35:55.138Z
Status : Received
Published: 2026-08-12T15:17:37.507
Modified: 2026-08-12T15:17:37.507
Link: CVE-2026-49349
No data.
OpenCVE Enrichment
Updated: 2026-08-13T10:39:26Z
Github GHSA