Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
References
| Link | Resource |
|---|---|
| https://github.com/apple/container/security/advisories/GHSA-m5rp-xcpf-r8m7 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-30 23:16
Updated : 2026-06-17 10:29
NVD link : CVE-2026-28909
Mitre link : CVE-2026-28909
CVE.ORG link : CVE-2026-28909
JSON object : View
Products Affected
apple
- container
CWE
CWE-522
Insufficiently Protected Credentials
