Authorization Flaw in Zot Container Image Registry by Project Zot
CVE-2026-31801
7.7HIGH
What is CVE-2026-31801?
The Zot container image registry, ranging from versions 1.3.0 to 2.1.14, displays an authorization flaw in its dist-spec middleware. By default, the middleware incorrectly infers the required action for PUT requests as 'create'. This misconfiguration allows users with create privileges, but without update rights, to bypass authorization checks, risking overwrites to existing tags, specifically when the 'latest' tag is concerned. This critical issue poses a significant risk and is resolved in version 2.1.15.
Affected Version(s)
zot >= 1.3.0, < v2.1.15
