HIGH7.5CVE-2026-35172Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
from 0, < 3.1.0
HIGH7.5CVE-2026-33540Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distribution
from 0, < 3.1.0
MEDIUM6.5CVE-2026-41888Distribution's tag deletion bypasses `storage.delete.enabled` configuration in github.com/distribution/distribution