CVE-2026-35172

Aliases:GHSA-f2g3-hh2r-cwgcDEBIAN-CVE-2026-35172BIT-distribution-2026-35172GO-2026-4942CGA-225r-xpj9-q3hhCGA-2rq4-mf52-8p3xCGA-482g-qg2g-jpwpCGA-4frf-35p3-jjg4CGA-4wxj-vjw5-mph2CGA-55wm-g4mh-243vCGA-639x-43mw-6wxvCGA-9xgr-rwph-x8w7CGA-c923-m844-w7v2CGA-chhq-gc29-m679CGA-fgw3-gh7x-8p7fCGA-fxcg-h4m8-q45hCGA-g2v7-6375-q8wmCGA-g9w9-rcp6-j8wxCGA-jrmw-w4g8-2p9mCGA-m6mp-wv9j-769jCGA-mqw8-9qw9-36v6CGA-pxg8-r7v7-p7q2CGA-2236-33f2-r5wwCGA-2797-hw65-7392CGA-2g4x-v7cq-q83fCGA-2g65-5j56-wj2xCGA-2mr2-wjp5-rc9qCGA-2v79-4h98-h9m2CGA-35h8-7ghw-7gx9CGA-3cg9-h9gq-mw4fCGA-3j38-9239-7g3cCGA-3jfg-qj36-cmq9CGA-3r8m-f9ww-54xcCGA-3vfm-q7vp-8qp6CGA-3vp4-5mxf-9wr3CGA-44gp-fj24-999cCGA-47q6-gwhx-5fj6CGA-4q44-9cpg-rgm9CGA-4wr9-h494-qmf7CGA-5565-9969-24x6CGA-59xc-f3m8-cxh7CGA-5mxx-j5f7-3pcvCGA-5rcv-7php-6mrqCGA-6c7w-pf7p-m9j7CGA-6h3g-53ch-7rpgCGA-6jqm-wghq-r7fvCGA-6v5m-m3wx-q45pCGA-6vpp-2wjp-992cCGA-72wx-pg5v-5hjgCGA-78fr-mvrg-f3wcCGA-7986-xg5m-28fxCGA-7gw6-m2xp-r44pCGA-7j7x-w5fc-j3gjCGA-7qw3-f8gp-h6g5CGA-7r53-fp7v-mm22CGA-7r66-ww44-9g9pCGA-7vqq-mp6c-mvp6CGA-826q-cpvr-9459CGA-82m3-g8g6-g3w8CGA-84p4-vq8v-5wqpCGA-8556-5fq9-j6h2CGA-8836-qgx7-pfr3CGA-8875-9vcq-jr62CGA-8jpm-53pq-55hfCGA-8pr3-8g8f-w6q8CGA-92qg-xh2m-x2qxCGA-9989-w6f3-h2vxCGA-9p9r-f49v-rjf7CGA-9pcv-qrqq-hg84CGA-9v47-m47v-8jg2CGA-9xqh-6jp9-63rfCGA-cfjf-347j-qgj6CGA-cgch-97f7-r762CGA-ch87-fr4h-vgv9CGA-cv85-x966-6mgfCGA-cv9m-mrr6-65c7CGA-cwxq-vr55-8rj9CGA-g3mf-2gh9-x253CGA-g7fj-j7j9-89hgCGA-gcgq-pj59-3pv8CGA-gm6g-9vp8-xfwwCGA-gp65-m7r2-gf4rCGA-gq9h-jph7-286hCGA-h338-rpg2-qm7gCGA-h593-mwjv-4j9gCGA-h5xx-hgx8-7x9gCGA-h97h-v32j-f85rCGA-hgxf-r4w3-92p9CGA-hhxm-fx7j-g62wCGA-hx6x-57cq-2w28CGA-j2wx-w958-xc6rCGA-j863-gqq5-vrj7CGA-j8wm-7wvv-47pxCGA-jm5h-5r32-gv4wCGA-jm82-3mg7-g65qCGA-jmfp-cvrj-64qvCGA-m3mj-52xv-4qjmCGA-m6vf-mwgc-mc9hCGA-m8fv-q9mc-5fjgCGA-mj24-gp24-9g77CGA-mj8r-ph9v-v2fmCGA-mvr6-39f9-vw7wCGA-mx79-76mx-pxjvCGA-p33x-jx3q-63hwCGA-p48h-7wv3-h394CGA-pm3f-x5hj-3h5hCGA-pm3g-w7qg-5vc6CGA-pqww-76x7-rgp8CGA-pv5m-hgrp-6662CGA-q84x-w44c-p8xgCGA-qjrg-gq94-53p2CGA-qmm8-gg6j-4gcgCGA-r3qx-phh9-43pxCGA-r7mx-7p8x-qc3gCGA-r8jv-cj23-5mxpCGA-r95x-7p7q-mxgxCGA-rw55-2jvv-q9ggCGA-rwfj-m4cp-f2hvCGA-rxgv-h2vh-742pCGA-v35v-5gm4-p73pCGA-v5wm-35wm-8853CGA-v9ph-3rcx-5c68CGA-vf6v-9j68-8vrcCGA-vf77-qvh4-mgh2CGA-vjpc-63v8-prqhCGA-vr4g-4v8g-x9h8CGA-vr6x-7xc2-gmrxCGA-vv5c-2vvm-cr5mCGA-wmcm-pjp2-xrwqCGA-x2v3-59c9-ww29CGA-x4cv-8p26-xxq7CGA-x836-hgmh-wmr2CGA-x878-cg4h-5p48CGA-x8fp-v2m7-4vhjCGA-xfr9-4r8m-hjpwCGA-xh23-99vw-gcrhCGA-xm36-9hhq-x5p9CGA-xq57-7x7w-57x3
Modified
Published: 06 Apr 2026, 19:08
Last modified:09 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.46% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

06 Apr 2026, 19:08
Published
Vulnerability first disclosed
09 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.46% Percentile: 39%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

  • CWE-524Use of Cache Containing Sensitive Information

    The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

Affected Systems

  • chainguardargocd-image-updater

    < 1.3.0-r0

  • chainguardargocd-image-updater-fips

    < 1.3.0-r0

  • chainguardenvoy-gateway-egctl

    < 1.7.1-r3

  • chainguardenvoy-gateway-fips-egctl

    < 1.7.1-r3

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    < 18.11.6-r0

  • chainguardgitlab-rails-ce-18.2

    all

  • chainguardgitlab-rails-ce-18.3

    all

  • chainguardgitlab-rails-ce-18.4

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.6-r0

  • chainguardgitlab-rails-ce-fips-18.2

    all

  • chainguardgitlab-rails-ce-fips-18.3

    all

  • chainguardgitlab-rails-ce-fips-18.4

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitness

    < 3.3.0-r12

  • chainguardharbor-2.12

    all

  • chainguardharbor-2.12-exporter

    all

  • chainguardharbor-2.12-jobservice

    all

  • chainguardharbor-2.12-registryctl

    all

  • chainguardharbor-2.13

    all

  • chainguardharbor-2.13-exporter

    all

  • chainguardharbor-2.13-jobservice

    all

  • chainguardharbor-2.13-registryctl

    all

  • chainguardharbor-2.14

    all

  • chainguardharbor-2.14-exporter

    all

  • chainguardharbor-2.14-jobservice

    all

  • chainguardharbor-2.14-registryctl

    all

  • chainguardharbor-2.15

    all

  • chainguardharbor-2.15-exporter

    all

  • chainguardharbor-2.15-jobservice

    all

  • chainguardharbor-2.15-registryctl

    all

  • chainguardharbor-fips-2.12

    all

  • chainguardharbor-fips-2.12-exporter

    all

  • chainguardharbor-fips-2.12-jobservice

    all

  • chainguardharbor-fips-2.12-registryctl

    all

  • chainguardharbor-fips-2.13

    all

Showing first 50 affected entries in server-rendered view.

References (16)