Authorization Flaw in Zot Container Image Registry by Project Zot
CVE-2026-31801

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
10 March 2026

What is CVE-2026-31801?

The Zot container image registry, ranging from versions 1.3.0 to 2.1.14, displays an authorization flaw in its dist-spec middleware. By default, the middleware incorrectly infers the required action for PUT requests as 'create'. This misconfiguration allows users with create privileges, but without update rights, to bypass authorization checks, risking overwrites to existing tags, specifically when the 'latest' tag is concerned. This critical issue poses a significant risk and is resolved in version 2.1.15.

Affected Version(s)

zot >= 1.3.0, < v2.1.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.