Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f2g3-hh2r-cwgc | Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation |
Tue, 28 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:* |
Wed, 08 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-524 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 07 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Distribution
Distribution distribution |
|
| Vendors & Products |
Distribution
Distribution distribution |
Mon, 06 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clears the shared digest descriptor but leaves stale repo-scoped membership behind, so a later Stat or Get from repo b repopulates the shared descriptor and makes the deleted blob readable from repo a again. This vulnerability is fixed in 3.1.0. | |
| Title | Distribution has stale blob access resurrection via repo-scoped redis descriptor cache invalidation | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-07T14:46:34.904Z
Reserved: 2026-04-01T17:26:21.133Z
Link: CVE-2026-35172
Updated: 2026-04-07T14:46:30.614Z
Status : Analyzed
Published: 2026-04-06T20:16:25.607
Modified: 2026-04-27T23:55:02.720
Link: CVE-2026-35172
OpenCVE Enrichment
Updated: 2026-04-28T21:45:26Z
Github GHSA