VDB
GO-2025-3460
GO-2025-3460
PUBLISHED
Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | distribution/distribution | 0, 0 |
Timeline
- Mar 3, 2025 CVE Published
- Feb 4, 2026 CVE Updated
- May 1, 2026 Security Advisory