Signature Bypass

github.com/distribution/distribution is vulnerable to Signature Bypass. The vulnerability is due to improper JSON Web Key (JWK) verification, allowing an attacker to forge a malicious JWT and bypass.. ...

Continue Reading
CVE-2025-26340

A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to bypass the auth ...

Continue Reading
CVE-2025-24976

A flaw was found in Distribution. Certain versions with token authentication enabled may be vulnerable to an issue where token authentication allows an attacker to inject an untrusted signing key in a ...

Continue Reading
Security update for SUSE Manager Client Tools

This update fixes the following issues: golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): Security issues fixed: CVE-2024-51744: Updated golang-jwt to ve ...

Continue Reading
Security update for SUSE Manager Client Tools

This update fixes the following issues: golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): Security issues fixed: CVE-2024-51744: Updated golang-jwt to ve ...

Continue Reading
Security update golang-github-prometheus-prometheus

golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): Security issues fixed: CVE-2024-51744: Updated golang-jwt to version 5.0 to fix bad error handling ...

Continue Reading
Security update golang-github-prometheus-prometheus

golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): Security issues fixed: CVE-2024-51744: Updated golang-jwt to version 5.0 to fix bad error handling ...

Continue Reading
Improper Authentication

github.com/distribution/distribution/v3 is vulnerable to Improper Authentication. The vulnerability is due to Improper Authentication due to inadequate verification of JSON Web Keys (JWK) in JSON Web ...

Continue Reading

Back to Main

Subscribe for the latest news: