CVE-2026-28909

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*

History

04 May 2026, 18:22

Type Values Removed Values Added
References () https://github.com/apple/container/security/advisories/GHSA-m5rp-xcpf-r8m7 - () https://github.com/apple/container/security/advisories/GHSA-m5rp-xcpf-r8m7 - Vendor Advisory
CPE cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*
First Time Apple
Apple container

01 May 2026, 14:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-522

30 Apr 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 23:16

Updated : 2026-05-04 18:22


NVD link : CVE-2026-28909

Mitre link : CVE-2026-28909

CVE.ORG link : CVE-2026-28909


JSON object : View

Products Affected

apple

  • container
CWE
CWE-522

Insufficiently Protected Credentials