Credentials Leakage Vulnerability in regclient by Go
CVE-2026-49349

6.8MEDIUM

Key Information:

Vendor

Regclient

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-49349?

regclient, a Docker and OCI Registry Client implemented in Go, has a vulnerability that allows for the potential leakage of credentials to external servers. This critical issue arises when interacting with a malicious registry server, a compromised blob store, or any registry that fails to restrict access to external URLs for foreign blobs. Users are advised to upgrade to version 0.11.5 or later to mitigate this significant security risk.

Affected Version(s)

regclient < 0.11.5

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.