CVE-2025-24976

EPSS 0.11%

Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution

Published: 3/3/2025Modified: 2/4/2026
Also known as:GHSA-phw4-mc57-4hwcCGA-96m3-mr7p-mx3fGO-2025-3460

Description

Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution

Affected packages (1)

References (3)