CVE-2026-65388 PUBLISHED

Assigner: apple
Reserved: 22.07.2026 Published: 16.09.2026 Updated: 16.09.2026

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.

Product Status

Vendor Apple
Product containerization
Versions
  • affected from 0 to 0.41.0 (excl.)

References

Problem Types

  • A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host.