OCI image scanning could expose registry credentials
Fixed in: malcontent 1.20.3
patched
details
Finding IDs
F-MALCONTENT-003
CVE
CVE-2026-24845
GHSA
GHSA-9m43-p3cx-w8j5
Status
patched
Fixed in
malcontent 1.20.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE registry state
PUBLISHED
CVE state checked
Upstream title
OCI image scanning could expose registry credentials
Upstream CWE
CWE-522
Upstream publication
Upstream updated
Metadata fetched
Upstream @1seal credit
@1seal: reporter (accepted)
F-MALCONTENT-003: Secret handling. The advisory describes exposure of registry credentials during OCI scanning. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.