---
id: CVE-2026-35172
title: 'Distribution is a toolkit to pack, ship, store, and deliver container content'
summary: >-
  Distribution is a toolkit to pack, ship, store, and deliver container content.
  Prior to 3.1.0, distribution can restore read access in repo a after an
  explicit delete when storage.cache.blobdescriptor: redis and
  storage.delete.enabled: t…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
  - CWE-524
vendor: distribution
product: distribution
affected:
  - distribution < 3.1.0
patched:
  - distribution 3.1.0
published: '2026-04-06'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:19:39.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35172'
references:
  - url: >-
      https://github.com/distribution/distribution/security/advisories/GHSA-f2g3-hh2r-cwgc
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:23234'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25045'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26529'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26543'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28893'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-35172'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2455571'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35172.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-35172'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35172'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-07T14:45:08.558570Z'
epss: 0.00455
epssPercentile: 0.38852
ingestedAt: '2026-07-02T12:34:40.479Z'
---

## Overview

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0.

## Affected

- `distribution < 3.1.0`

## Remediation

Upgrade past the affected range:

- `distribution 3.1.0`

## Vendor advisories

- **RHSA-2026:26529** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:26529)
- **RHSA-2026:26543** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:26543)
- **RHSA-2026:28893** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:28893)
- **RHSA-2026:23234** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:23234)
- **RHSA-2026:25045** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-06-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:25045)
- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · no fix planned: Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35172.json)
