ZeroHour

CVE-2026-28909

CVSS 3.1
6.5 medium
EPSS
<1%p10
Published
()
Modified
Description

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Vendors
apple
Products
container
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.