Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-41190

20
FAUCET Score

CVE-2021-41190 affects the OCI Distribution Specification (versions 1.0.0 and prior), including related Fedora and Linux Foundation products. This vulnerability arises from ambiguous interpretation of content during push/pull operations when the Content-Type header is missing or inconsistent, potentially leading to a client misinterpreting a document as either a manifest or an index. With a CVSS score of 5.0 (Medium), it has a low attack complexity and requires low privileges, but its impact is limited to low integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.0CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:open_container_initiative_distribution_specification:*:*:*:*:*:*:*:*
<= 1.0.1CPE matchmatch criteria
cpe:2.3:a:linuxfoundation:open_container_initiative_image_format_specification:*:*:*:*:*:*:*:*
34CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.0LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.08%
Probability of exploitation in next 30 days
EPSS Percentile
79.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0209 is in the 91st percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/opencontainers/distribution-specFixed in: 1.0.1
redhatpatch availablevia redhat_api
Product: RHACS-3.70-RHEL-8Fixed in: advanced-cluster-security/rhacs-roxctl-rhel8:3.70.0-2
View patch
redhatpatch availablevia redhat_api
Product: OADP-1.0-RHEL-8Fixed in: oadp/oadp-registry-rhel8:1.0.1-3
View patch
redhatpatch availablevia redhat_api
Product: OADP-1.0-RHEL-8Fixed in: oadp/oadp-velero-plugin-rhel8:1.0.1-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8070020220929222448.39077419
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Migration Toolkit for Containers 1.7Fixed in: rhmtc/openshift-migration-controller-rhel8:v1.7.1-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.10Fixed in: cri-o-0:1.23.0-92.rhaos4.10.gitdaab4d1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.11Fixed in: openshift4/ose-docker-builder:v4.11.0-202208020235.p0.gb500d85.assembly.stream
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.70-RHEL-8Fixed in: advanced-cluster-security/rhacs-collector-rhel8:3.70.0-2
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.70-RHEL-8Fixed in: advanced-cluster-security/rhacs-docs-rhel8:3.70.0-2
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.70-RHEL-8Fixed in: advanced-cluster-security/rhacs-main-rhel8:3.70.0-9
View patch
redhatpatch availablevia redhat_api
Product: RHACS-3.70-RHEL-8Fixed in: advanced-cluster-security/rhacs-rhel8-operator:3.70.0-2
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Virtualization 2Fixed in: virt-cdi-importer-container
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-file-integrity-operator-container
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: podman
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: skopeo
redhatvendor investigatingvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-builder-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:3.0/buildah
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:3.0/podman
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:3.0/skopeo
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-operator-sdk-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-clients
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-compliance-openscap-container
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift-compliance-operator-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/virt-cdi-importer
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: buildah
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: podman

Vendor Advisories (2)

goGHSA-mc8v-mgrf-8f4mlow

Clarify Content-Type handling

Nov 18, 2021
redhatCVE-2021-41190Low

opencontainers: OCI manifest and index parsing confusion

Nov 17, 2021

References

github.com / opencontainers/distribution-spec/commit/ac28cac0557bcd3084714ab09f9f2356fe504923
PatchThird Party Advisory
github.com / opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/3TUZNDAH2B26VPBK342UC3BHZNLBUXGX
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4334HT7AZPLWNYHW4ARU6JBUF3VZJPZN
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/A2RRFNTMFYKOTRKD37F5ANMCIO3GGJML
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/DX63GRWFEI5RVMYV6XLMCG4OHPWZML27
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/RZTO6N55WHKHIZI4IMLY2QFBPMVTAERM
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/SQBCYJUIM5GVCMFUPRWKRZNXMMI5EFA4
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/T4OJ764CKKCWCVONHD4YXTGR7HZ7LRUV
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/YIGVQWOA5XXCQXEOOKZX4CDAGLBDRPRX
openwall.com / lists/oss-security/2021/11/19/10
Mailing ListThird Party Advisory