Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6pjf-3r9x-m592 | Distribution's tag deletion bypasses `storage.delete.enabled` configuration |
Fri, 15 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 14 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Distribution
Distribution distribution |
|
| Vendors & Products |
Distribution
Distribution distribution |
Thu, 14 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1. | |
| Title | Distribution: Tag deletion bypasses `storage.delete.enabled` configuration | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T18:38:43.215Z
Reserved: 2026-04-22T15:11:54.671Z
Link: CVE-2026-41888
Updated: 2026-05-14T18:38:37.491Z
Status : Analyzed
Published: 2026-05-14T18:16:47.380
Modified: 2026-05-15T18:25:48.043
Link: CVE-2026-41888
No data.
OpenCVE Enrichment
Updated: 2026-05-14T18:45:26Z
Github GHSA