Stale blob access resurrection via repo-scoped redis descriptor cache invalidation
Upstream fixed versions: package name not specified: >=3.1.0
details
- Finding IDs
- F-DIST-REDIS-REVIVAL-001
- CVE
- CVE-2026-35172
- GHSA
- GHSA-f2g3-hh2r-cwgc
- Status
- patched
- Fixed in
- package name not specified: >=3.1.0
- Note
- GHSA-f2g3-hh2r-cwgc
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Stale blob access resurrection via repo-scoped redis descriptor cache invalidation
- Upstream CWE
- CWE-284
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- package name not specified: >=3.1.0
- Upstream affected ranges
- package name not specified: <= 3.0.x, <= 2.8.x when redis blob descriptor cache and delete are both enabled
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-DIST-REDIS-REVIVAL-001: Access control. Stale cached access state revives access that should no longer be granted. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-DIST-REDIS-REVIVAL-001
Security area (1seal assessment): Authorization. Stale cached access state revives access that should no longer be granted. Reviewed 24 Sep 2026.