Authentication Flaw in Pulp-Container Affects Red Hat Products
CVE-2026-103868

6.5MEDIUM

What is CVE-2026-103868?

A significant flaw has been identified in the Pulp-Container tool that compromises the authentication process when connecting to an upstream registry. This vulnerability allows basic and bearer credentials from one remote to be reused during subsequent downloads within the same worker. If a user can synchronize a container remote and directs that remote to a server they control, they gain access to the username, password, or bearer token associated with a different remote. This potentially allows attackers to leverage these credentials at the upstream registry while the content stored in Pulp remains unchanged, and the service continues operating.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Daoqing Yu for reporting this issue.
.