VYPR
Medium severity6.8NVD Advisory· Published Aug 12, 2026· Updated Sep 9, 2026

CVE-2026-49349

CVE-2026-49349

Description

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict the external URLs for foreign blobs. Version 0.11.5 fixes the issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/regclient/regclientGo
< 0.11.50.11.5

Affected products

24

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.