Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9m43-p3cx-w8j5 | malcontent OCI image pull credential exfiltration via malicious registry token realm |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 30 Jan 2026 07:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 06:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a `WWW-Authenticate` header redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint. Version 1.20.3 fixes the issue by defaulting to anonymous auth for OCI pulls. | |
| Title | malcontent's OCI image scanning could expose registry credentials | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-29T21:40:17.926Z
Reserved: 2026-01-27T14:51:03.059Z
Link: CVE-2026-24845
Updated: 2026-01-29T21:39:51.850Z
Status : Received
Published: 2026-01-29T22:15:54.583
Modified: 2026-01-29T22:15:54.583
Link: CVE-2026-24845
No data.
OpenCVE Enrichment
No data.
Github GHSA