
Pull-through cache bug leaks upstream registry credentials
CVE-2026-33540 reports a High-severity credential exfiltration risk in `distribution` pull-through cache mode, where attacker-controlled `WWW-Authenticate` `realm` redirects basic-auth credentials.
NewsContainer SecurityDevSecOps
2 minYesterday
