---
id: CVE-2026-65388
title: >-
  A remote attacker who controls a container registry may be able to direct a
  client's token request to a host of the attacker's choice, and disclose the
  victim's registry credentials to that host
summary: >-
  A remote attacker who controls a container registry may be able to direct a
  client's token request to a host of the attacker's choice, and disclose the
  victim's registry credentials to that host. This vulnerability is addressed in
  contai…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-601
vendor: Apple
product: containerization
affected:
  - containerization < 0.41.0
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T17:48:19.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-65388'
references:
  - url: >-
      https://github.com/apple/containerization/security/advisories/GHSA-mx96-5vvg-x2mg
    label: product-security@apple.com
tags:
  - nvd
  - cve.org
epss: 0.00272
epssPercentile: 0.19816
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T13:05:32.107756Z'
ingestedAt: '2026-09-16T23:07:58.097Z'
---

## Overview

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
