Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35172

29
FAUCET Score

CVE-2026-35172 is an information disclosure vulnerability affecting the Distribution container toolkit prior to version 3.1.0. When both Redis caching and deletion features are enabled, the flaw allows deleted blobs to become readable again through a different repository due to incomplete cleanup of digest descriptors, potentially exposing sensitive container content that should have been permanently removed. The vulnerability presents a high-severity risk with a CVSS score of 7.5, requiring no authentication, user interaction, or special access complexity to exploit remotely. The attack vector is network-based with confidentiality impact rated as high, though integrity and availability remain unaffected. The EPSS score of 0.00042 indicates minimal prevalence among publicly disclosed vulnerabilities. There is currently no evidence of active exploitation, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and marked as inactive on threat tracking lists. No public exploit code has been reported, and community attention remains limited. Organizations should prioritize patching to version 3.1.0 or later, particularly those operating Distribution with both Redis blob descriptor caching and deletion functionality enabled in production container registries.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.1.0CPE matchmatch criteria
cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.46%
Probability of exploitation in next 30 days
EPSS Percentile
37.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0046 is in the 16th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/distribution/distribution/v3Fixed in: 3.1.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-f2g3-hh2r-cwgchigh

Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation

Apr 6, 2026

References

access.redhat.com / errata/RHSA-2026:23234
access.redhat.com / errata/RHSA-2026:25045
access.redhat.com / errata/RHSA-2026:26529
access.redhat.com / errata/RHSA-2026:26543
access.redhat.com / errata/RHSA-2026:28893
access.redhat.com / errata/RHSA-2026:37387
access.redhat.com / security/cve/CVE-2026-35172
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-35172.json
github.com / distribution/distribution/security/advisories/GHSA-f2g3-hh2r-cwgc
ExploitVendor Advisory