Authentication Flaw in Pulp-Container Affects Red Hat Products
CVE-2026-103868
6.5MEDIUM
What is CVE-2026-103868?
A significant flaw has been identified in the Pulp-Container tool that compromises the authentication process when connecting to an upstream registry. This vulnerability allows basic and bearer credentials from one remote to be reused during subsequent downloads within the same worker. If a user can synchronize a container remote and directs that remote to a server they control, they gain access to the username, password, or bearer token associated with a different remote. This potentially allows attackers to leverage these credentials at the upstream registry while the content stored in Pulp remains unchanged, and the service continues operating.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Daoqing Yu for reporting this issue.