Manifest Digest Manipulation in regclient by a Malicious Registry
CVE-2025-24882
5.2MEDIUM
What is CVE-2025-24882?
A vulnerability exists in regclient, which is a Docker and OCI Registry Client developed in Go. This flaw allows a malicious registry to return a falsified digest for a pinned manifest, leading to potential security risks. Users are advised to update to version 0.7.1 or later to mitigate this issue.
Affected Version(s)
regclient < 0.7.1
