CVE-2026-103868Medium· 6.5▾ SunlitA flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103869Medium· 6.5A flaw was found in pulp-ansible's bearer-token refresh for collection remotes
CVE-2026-90959High· 8.1A path traversal vulnerability was found in pulpcore
CVE-2026-84232Medium· 5.4Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content
CVE-2026-107121Medium· 6.5A flaw was found in the SMTP email configuration handling of the keycloak-services component
CVE-2026-103870Medium· 5.0A flaw was found in pulp-rpm when it publishes a distribution tree
CVE-2026-106061Medium· 5.5A flaw was found in GIMP’s X cursor (XMC) thumbnail loader