Credentials Leakage Vulnerability in regclient by Go
CVE-2026-49349
6.8MEDIUM
What is CVE-2026-49349?
regclient, a Docker and OCI Registry Client implemented in Go, has a vulnerability that allows for the potential leakage of credentials to external servers. This critical issue arises when interacting with a malicious registry server, a compromised blob store, or any registry that fails to restrict access to external URLs for foreign blobs. Users are advised to upgrade to version 0.11.5 or later to mitigate this significant security risk.
Affected Version(s)
regclient < 0.11.5
