CVE-2025-24882

regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) regclient es un cliente de registro de Docker y OCI en Go. Un registro malintencionado podría devolver un resumen diferente para un manifiesto anclado sin que se lo detecte. Esta vulnerabilidad se solucionó en la versión 0.7.1.

29 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 18:15

Updated : 2026-06-17 08:59


NVD link : CVE-2025-24882

Mitre link : CVE-2025-24882

CVE.ORG link : CVE-2025-24882


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-345

Insufficient Verification of Data Authenticity