Medium severity5.9NVD Advisory· Published Apr 28, 2026· Updated May 5, 2026
CVE-2026-33467
CVE-2026-33467
Description
Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/elastic/package-registryGo | < 1.38.0 | 1.38.0 |
Affected products
1- cpe:2.3:a:elastic:elastic_package_registry:*:*:*:*:*:*:*:*Range: <1.38.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- discuss.elastic.co/t/elastic-package-registry-1-38-0-security-update-esa-2026-27/386081nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-r727-5pf6-47r2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33467ghsaADVISORY
News mentions
0No linked articles in our index yet.