VYPR
Medium severity6.5NVD Advisory· Published Apr 30, 2026· Updated May 4, 2026

CVE-2026-28909

CVE-2026-28909

Description

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

49