docker fetcher: strip sensitive headers on descriptor URLs
details
- Finding IDs
- F-CONTAINERD-DESCURLS-001
- Status
- merged
- Reported date
- Rationale
- prevents registry-scoped Authorization, Proxy-Authorization, Cookie, and Cookie2 headers from being forwarded to cross-origin descriptor URLs while preserving same-origin registry behavior. public PR #12889 merged into main on 2026-08-25 as commit d7bebd8.
- PR opened by
- @1seal
- PR state observed
- closed; GitHub merged: true; 2026-09-24
- PR observation basis
- Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed.
- Contribution boundary
- @1seal opened this PR; this alone does not establish sole code authorship.
F-CONTAINERD-DESCURLS-001: Outbound request trust. Descriptor URLs can receive sensitive headers intended for a different destination. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CONTAINERD-DESCURLS-001
Security area (1seal assessment): Authorization. Descriptor URLs can receive sensitive headers intended for a different destination. Reviewed 24 Sep 2026.