CVE-2026-24845 describes a vulnerability in Chainguard malcontent versions 0.10.0 through 1.20.2, where scanning a specially crafted OCI image reference could expose Docker registry credentials. A malicious registry could redirect token authentication to an attacker-controlled endpoint via a WWW-Authenticate header, leading to credential leakage. This medium-severity vulnerability (CVSS 6.5) has a network attack vector and low attack complexity, requiring user interaction (scanning the malicious image). The primary impact is high confidentiality compromise, as credentials could be stolen. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 1.20.3CPE matchmatch criteria | cpe:2.3:a:chainguard:malcontent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.