CVE-2025-24976 Distribution’s token authentication allows attacker to inject an untrusted signing key in a JWT

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to ...

Continue Reading
CVE-2025-24976

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to ...

Continue Reading
GHSA-9WX4-H78V-VM56 vulnerabilities

Vulnerabilities for packages: kubeflow-jupyter-web-app, datadog-agent, k8s-sidecar, reflex, py3.11-torchvision-cuda-11.8, kubeflow-volumes-web-app, mlflow, apache-beam-python-3.11-sdk, ggshield, jwt-t ...

Continue Reading
CVE-2024-35195 vulnerabilities

Vulnerabilities for packages: kubeflow-jupyter-web-app, datadog-agent, k8s-sidecar, reflex, py3.11-torchvision-cuda-11.8, kubeflow-volumes-web-app, mlflow, apache-beam-python-3.11-sdk, ggshield, jwt-t ...

Continue Reading
CVE-2023-5752 vulnerabilities

Vulnerabilities for packages: k8s-sidecar,...Read More ...

Continue Reading
GHSA-9WX4-H78V-VM56 vulnerabilities

Vulnerabilities for packages: kubeflow-jupyter-web-app, datadog-agent, k8s-sidecar, reflex, py3.11-torchvision-cuda-11.8, kubeflow-volumes-web-app, mlflow, apache-beam-python-3.11-sdk, ggshield, jwt-t ...

Continue Reading
GHSA-MQ26-G339-26XF vulnerabilities

Vulnerabilities for packages: k8s-sidecar,...Read More ...

Continue Reading
CVE-2024-35195 vulnerabilities

Vulnerabilities for packages: kubeflow-jupyter-web-app, datadog-agent, k8s-sidecar, reflex, py3.11-torchvision-cuda-11.8, kubeflow-volumes-web-app, mlflow, apache-beam-python-3.11-sdk, ggshield, jwt-t ...

Continue Reading

Back to Main

Subscribe for the latest news: