| id: GO-2025-3460 |
| modules: |
| - module: github.com/distribution/distribution |
| unsupported_versions: |
| - cve_version_range: affected at >= 3.0.0-beta.1, <= 3.0.0-rc.2 |
| vulnerable_at: 2.8.3+incompatible |
| summary: |- |
| Distribution's token authentication allows attacker to inject an untrusted |
| signing key in a JWT in github.com/distribution/distribution |
| cves: |
| - CVE-2025-24976 |
| ghsas: |
| - GHSA-phw4-mc57-4hwc |
| references: |
| - advisory: https://github.com/distribution/distribution/security/advisories/GHSA-phw4-mc57-4hwc |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-24976 |
| - fix: https://github.com/distribution/distribution/commit/5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd |
| source: |
| id: CVE-2025-24976 |
| created: 2025-03-03T11:02:00.475963-05:00 |
| review_status: UNREVIEWED |