Supply-Chain Compromise in Malcontent Docker Registry Credentials Exposure
CVE-2026-24845
6.5MEDIUM
What is CVE-2026-24845?
A vulnerability in Malcontent allows for exposure of Docker registry credentials when scanning specially crafted OCI image references. Versions 0.10.0 through 1.20.2 use the Docker credential keychain by default, potentially allowing malicious registries to redirect authentication tokens to unauthorized endpoints through a WWW-Authenticate header. This flaw enables attackers to intercept sensitive credential data. The issue is mitigated in version 1.20.3 which defaults to anonymous authentication for OCI pulls, reducing the risk of credential exposure.
Affected Version(s)
malcontent >= 0.10.0, < 1.20.3
