CVE-2026-41888
Vulnerability Summary
Timeline
Description
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- v4.0•MEDIUM•Score: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
EPSS Trends
Current EPSS score: 0.29%• Percentile: 22%
Techniques & Countermeasures
- CWE-863•Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Affected Systems
- chainguard•argocd-image-updater
< 1.3.0-r0
- chainguard•argocd-image-updater-fips
< 1.3.0-r0
- chainguard•envoy-gateway-egctl
< 1.7.2-r5
- chainguard•envoy-gateway-fips-egctl
< 1.7.2-r2 | < 1.7.2-r3
- chainguard•gitlab-rails-ce-18.1
< 18.1.6-r10
- chainguard•gitlab-rails-ce-18.10
< 18.10.5-r1
- chainguard•gitlab-rails-ce-18.11
< 18.11.6-r0
- chainguard•gitlab-rails-ce-18.3
all
- chainguard•gitlab-rails-ce-18.4
all
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
< 18.6.6-r4
- chainguard•gitlab-rails-ce-18.7
< 18.7.6-r3
- chainguard•gitlab-rails-ce-18.8
< 18.8.9-r1
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
all
- chainguard•gitlab-rails-ce-fips-18.1
all
- chainguard•gitlab-rails-ce-fips-18.10
< 18.10.4-r1
- chainguard•gitlab-rails-ce-fips-18.11
< 18.11.6-r0
- chainguard•gitlab-rails-ce-fips-18.3
< 18.3.6-r7
- chainguard•gitlab-rails-ce-fips-18.4
all
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
< 18.6.6-r4
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
< 18.9.6-r1
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•gitness
< 3.3.0-r16
- chainguard•harbor-2.12
all
- chainguard•harbor-2.12-exporter
all
- chainguard•harbor-2.12-jobservice
all
- chainguard•harbor-2.12-registryctl
all
- chainguard•harbor-2.13
all
- chainguard•harbor-2.13-exporter
all
- chainguard•harbor-2.13-jobservice
all
- chainguard•harbor-2.13-registryctl
all
- chainguard•harbor-2.14
all
- chainguard•harbor-2.14-exporter
all
- chainguard•harbor-2.14-jobservice
all
- chainguard•harbor-2.14-registryctl
all
- chainguard•harbor-2.15
all
- chainguard•harbor-2.15-exporter
all
- chainguard•harbor-2.15-jobservice
all
- chainguard•harbor-2.15-registryctl
all
- chainguard•harbor-fips-2.12
all
- chainguard•harbor-fips-2.12-exporter
all
- chainguard•harbor-fips-2.12-jobservice
all
- chainguard•harbor-fips-2.12-registryctl
all
- chainguard•harbor-fips-2.13
all
- chainguard•harbor-fips-2.13-exporter
all
- chainguard•harbor-fips-2.13-jobservice
all
Showing first 50 affected entries in server-rendered view.
References (5)
- https://github.com/distribution/distribution/security/advisories/GHSA-6pjf-3r9x-m592
- https://github.com/distribution/distribution
- https://nvd.nist.gov/vuln/detail/CVE-2026-41888
- https://security-tracker.debian.org/tracker/CVE-2026-41888
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41888.json