CVE-2026-35172 is an information disclosure vulnerability affecting the Distribution container toolkit prior to version 3.1.0. When both Redis caching and deletion features are enabled, the flaw allows deleted blobs to become readable again through a different repository due to incomplete cleanup of digest descriptors, potentially exposing sensitive container content that should have been permanently removed. The vulnerability presents a high-severity risk with a CVSS score of 7.5, requiring no authentication, user interaction, or special access complexity to exploit remotely. The attack vector is network-based with confidentiality impact rated as high, though integrity and availability remain unaffected. The EPSS score of 0.00042 indicates minimal prevalence among publicly disclosed vulnerabilities. There is currently no evidence of active exploitation, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and marked as inactive on threat tracking lists. No public exploit code has been reported, and community attention remains limited. Organizations should prioritize patching to version 3.1.0 or later, particularly those operating Distribution with both Redis blob descriptor caching and deletion functionality enabled in production container registries.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0CPE matchmatch criteria | cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.