CVE-2026-61833High· 8.1▾ Twilightzot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandler path in pkg/api/authz.go, while DeleteManifest and DeleteBlob perform no independent delete-permission check. A remote attacker with a bearer token limited to pull and push actions can therefore delete manifests and blobs within the token's repository scope, making images unavailable and allowing repository history to be altered despite the token lacking delete authorization. This issue is fixed in version 2.1.18.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
zotregistry.dev/zot/v2 < 2.1.18Patched in:
zotregistry.dev/zot/v2 2.1.18Connected by shared product, vendor, weakness, or advisory.
CVE-2024-39897Medium· 4.3Cache driver GetBlob() allows read access to any blob without access control check
CVE-2026-55236Medium· 5.9langgraph-api implements the LangGraph API for rapid development and testing
CVE-2026-49446Medium· 6.1Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager
CVE-2026-55775Low· 2.3OpenBao is an open source identity-based secrets management system
CVE-2026-94379Medium· 6.9The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths
CVE-2026-94152Medium· 4.3A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025