CVE-2026-41888

Aliases:GHSA-6pjf-3r9x-m592GO-2026-5185DEBIAN-CVE-2026-41888BIT-distribution-2026-41888CGA-298q-jwhq-587mCGA-3mmx-9p9f-c4v9CGA-53pf-2hj4-5mc2CGA-57g8-rp7m-hjp4CGA-5w5w-c5fp-vjc7CGA-5xr5-3jmv-xcg9CGA-79r8-gqp7-g6gmCGA-8r4q-29wp-q4jpCGA-c98r-23rp-f93mCGA-c9rv-6gxf-j29fCGA-cr62-r73r-w8jqCGA-f96r-6c4c-phvxCGA-fxm8-c4cf-4cqjCGA-gfgc-w4r4-rwm8CGA-h88w-5m2q-7x8vCGA-h9p6-xv5h-39f2CGA-j976-7h3j-m8g2CGA-jgcg-2jv3-w4fhCGA-23qh-35w9-2g22CGA-2486-732p-3627CGA-2gfg-w6c5-76rmCGA-2jfq-2cfw-vc2hCGA-2jqg-93qq-7rv4CGA-2rj4-v6fh-cm8vCGA-33m8-672j-6g3gCGA-35fg-q25f-324fCGA-36xr-65mq-fg83CGA-39w4-7fqv-q4mfCGA-3jm9-7c4p-9x6fCGA-3qwj-rvr8-c6qhCGA-3r36-gr37-rcw3CGA-46r9-f28p-pgv9CGA-47rm-p442-c54hCGA-4cxf-pxmh-xhvfCGA-4g3w-m6fg-wpxqCGA-4wxw-fprw-694wCGA-539m-8j96-c4wjCGA-55vx-pj9w-cc8mCGA-59pr-r6cj-6vcmCGA-5crc-mrg8-84x4CGA-5fv7-576x-3vvjCGA-5jgc-2mq5-2c2jCGA-5p9r-69f4-r23qCGA-5q6h-ww7c-j83qCGA-5x7j-xp4p-w65vCGA-6ph7-3368-hr8wCGA-6qw7-pgjr-pq76CGA-6xqx-jrv8-w5m7CGA-7273-67rj-qwxhCGA-8c44-pjfm-r2r9CGA-8m24-3hjp-q8j8CGA-8vh2-xm8f-xc4cCGA-94jw-pp8j-35qpCGA-99cw-xmjx-h9xhCGA-9c3j-m6mp-2fhwCGA-9g4c-75m7-xxgxCGA-9jxj-hrjr-mr8xCGA-9v35-838m-7fw5CGA-9xgp-hj68-qp3jCGA-c43c-gccv-v62fCGA-c7f6-hgqf-56w3CGA-c832-cj9c-g6r4CGA-cfrc-6gq7-jvhvCGA-cjrj-cv4v-q296CGA-cpmw-h9jh-8j3vCGA-f6gv-j8jv-w8p9CGA-fcj2-jg94-rvmxCGA-fhpj-gqpw-6rq6CGA-fjmg-ffrp-cmm8CGA-fq4f-qg7x-j5f6CGA-fqr2-gxrr-p5fmCGA-fv85-v2rh-vc8qCGA-g6r9-xh7f-qwxwCGA-g9m5-fgc5-g525CGA-gfq8-r9gj-cvvmCGA-gq56-cf97-4r5hCGA-gxp5-fxh7-9pvjCGA-h5hc-9752-5454CGA-hm7x-5hjj-4rh3CGA-hw89-hcx3-rpmxCGA-j2qw-6cgg-jxhxCGA-j3g7-x7gw-f9g5CGA-j3m8-m98x-cw2mCGA-jfqh-j88f-wj7pCGA-jh54-hgqp-qx2fCGA-jp58-6cp8-w4pxCGA-jp77-w88m-qc44CGA-jpv3-crhg-xh2gCGA-m88h-94fr-7xvrCGA-m8r6-5hm4-37pmCGA-mmmw-66jc-phw8CGA-mrvq-7q7w-j52fCGA-mvg5-c64x-275cCGA-mxxx-3mg3-xmvhCGA-p3rj-wj78-fjcvCGA-pf9v-g47f-v2m2CGA-pqj9-5rgp-q8g9CGA-pvqw-86gj-jc9jCGA-q8cw-jwfx-8px8CGA-qmvv-538f-22g8CGA-r49f-27vw-8v97CGA-r7fq-q4wx-3v52CGA-r7hh-g8p3-56f4CGA-rg59-gw82-x7grCGA-rhcr-9rgm-53wwCGA-rj32-wwm7-rgcmCGA-rm9g-h3vg-pww3CGA-v8gm-vv6h-3xfmCGA-vj2r-2w64-9p28CGA-vmm5-jv46-pmfvCGA-vwh5-rj32-hmh6CGA-vx59-3xrp-v2q2CGA-w27m-8cqq-3r6mCGA-w5v8-hmwg-87vjCGA-wf8p-v82f-4c4rCGA-wh53-3q2c-h7qjCGA-wmv6-pp86-w9xcCGA-wp8v-7crp-2wq2CGA-wv95-r8jw-f2fhCGA-x367-wcfm-2mrvCGA-x6m3-r9h9-45jqCGA-x7j3-55qx-fqjvCGA-x9mc-6vfr-7vwgCGA-xqqg-wvhj-2h9gCGA-xqqq-v3m5-p924CGA-xrg5-8mgr-5p2m
Analyzed
Published: 14 May 2026, 16:53
Last modified:14 May 2026, 18:38

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.29% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

14 May 2026, 16:53
Published
Vulnerability first disclosed
14 May 2026, 18:38
Last Modified
Vulnerability information updated

Description

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.

CVSS Metrics

  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

EPSS Trends

Current EPSS score: 0.29% Percentile: 22%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Systems

  • chainguardargocd-image-updater

    < 1.3.0-r0

  • chainguardargocd-image-updater-fips

    < 1.3.0-r0

  • chainguardenvoy-gateway-egctl

    < 1.7.2-r5

  • chainguardenvoy-gateway-fips-egctl

    < 1.7.2-r2 | < 1.7.2-r3

  • chainguardgitlab-rails-ce-18.1

    < 18.1.6-r10

  • chainguardgitlab-rails-ce-18.10

    < 18.10.5-r1

  • chainguardgitlab-rails-ce-18.11

    < 18.11.6-r0

  • chainguardgitlab-rails-ce-18.3

    all

  • chainguardgitlab-rails-ce-18.4

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    < 18.6.6-r4

  • chainguardgitlab-rails-ce-18.7

    < 18.7.6-r3

  • chainguardgitlab-rails-ce-18.8

    < 18.8.9-r1

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    < 18.10.4-r1

  • chainguardgitlab-rails-ce-fips-18.11

    < 18.11.6-r0

  • chainguardgitlab-rails-ce-fips-18.3

    < 18.3.6-r7

  • chainguardgitlab-rails-ce-fips-18.4

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    < 18.6.6-r4

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    < 18.9.6-r1

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitness

    < 3.3.0-r16

  • chainguardharbor-2.12

    all

  • chainguardharbor-2.12-exporter

    all

  • chainguardharbor-2.12-jobservice

    all

  • chainguardharbor-2.12-registryctl

    all

  • chainguardharbor-2.13

    all

  • chainguardharbor-2.13-exporter

    all

  • chainguardharbor-2.13-jobservice

    all

  • chainguardharbor-2.13-registryctl

    all

  • chainguardharbor-2.14

    all

  • chainguardharbor-2.14-exporter

    all

  • chainguardharbor-2.14-jobservice

    all

  • chainguardharbor-2.14-registryctl

    all

  • chainguardharbor-2.15

    all

  • chainguardharbor-2.15-exporter

    all

  • chainguardharbor-2.15-jobservice

    all

  • chainguardharbor-2.15-registryctl

    all

  • chainguardharbor-fips-2.12

    all

  • chainguardharbor-fips-2.12-exporter

    all

  • chainguardharbor-fips-2.12-jobservice

    all

  • chainguardharbor-fips-2.12-registryctl

    all

  • chainguardharbor-fips-2.13

    all

  • chainguardharbor-fips-2.13-exporter

    all

  • chainguardharbor-fips-2.13-jobservice

    all

Showing first 50 affected entries in server-rendered view.

References (5)