VDB
GHSA-f2g3-hh2r-cwgc
GHSA-f2g3-hh2r-cwgc
PUBLISHED
CVSS 7.5 HIGH
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| chainguard | gitness | 0, 0, 0 |
| wolfi | kots | 0, 0, 0 |
| wolfi | portieris | 0, 0, 0 |
| wolfi | envoy-gateway | 0, 0, 0 |
| github.com | distribution/distribution | 0, 0, 0 |
| chainguard | envoy-gateway-fips | 0, 0, 0 |
| chainguard | envoy-gateway | 0, 0, 0 |
| wolfi | gitness | 0, 0, 0 |
| chainguard | argocd-image-updater | 0, 0, 0 |
| chainguard | kots | 0, 0, 0 |
| chainguard | portieris-fips | 0, 0, 0 |
| github.com | distribution/distribution/v3 | 0, 0, 0 |
| chainguard | gitlab-rails-ce-18.11 | 0, 0, 0 |
| chainguard | zot | 0, 0, 0 |
| chainguard | argocd-image-updater-fips | 0, 0, 0 |
| wolfi | zot | 0, 0, 0 |
| wolfi | argocd-image-updater | 0, 0, 0 |
| chainguard | gitlab-rails-ce-fips-18.11 | 0, 0, 0 |
| chainguard | portieris | 0, 0, 0 |
Timeline
- Apr 6, 2026 CVE Published
- Apr 6, 2026 CVE Updated
- Apr 29, 2026 Security Advisory