blob: 7bd26a557c4a5656d8ebf87d12ed4cd48687461e [file] [edit]
id: GO-2026-4668
modules:
- module: zotregistry.dev/zot
non_go_versions:
- introduced: 1.3.0-20210831063041-c8779d9e87d9
unsupported_versions:
- last_affected: 1.4.4-20251014054906-73eef25681af
vulnerable_at: 1.4.3
- module: zotregistry.dev/zot/v2
versions:
- fixed: 2.1.15
vulnerable_at: 2.1.14
summary: |-
zot’s create-only policy allows overwrite attempts of existing latest tag
(update permission not required) in zotregistry.dev/zot
cves:
- CVE-2026-31801
ghsas:
- GHSA-85jx-fm8m-x8c6
references:
- advisory: https://github.com/project-zot/zot/security/advisories/GHSA-85jx-fm8m-x8c6
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-31801
- web: https://github.com/project-zot/zot/releases/tag/v2.1.15
source:
id: GHSA-85jx-fm8m-x8c6
created: 2026-03-12T19:42:56.978333187Z
review_status: UNREVIEWED