pkg:Go/github.com/distribution/distribution
5 total CVEsHIGH3MEDIUM1
✅ Check your installed version
All known vulnerabilities
- HIGH7.5CVE-2026-35172Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidationfrom 0, <= 2.8.3
- HIGH7.5CVE-2026-33540Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realmfrom 0, <= 2.8.3
- from 0, < 2.8.2-beta.1+incompatible
- from 0, <= 2.8.3
- —CVE-2025-24976Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distributionfrom 0