Insufficiently Protected Credentials Affecting github.com/regclient/regclient/internal/reghttp package, versions <0.11.5


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMREGCLIENTREGCLIENTINTERNALREGHTTP-17750723
  • published1 Jul 2026
  • disclosed26 Jun 2026
  • creditUnknown

Introduced: 26 Jun 2026

CVE-2026-49349  (opens in a new tab)
CWE-522  (opens in a new tab)

How to fix?

Upgrade github.com/regclient/regclient/internal/reghttp to version 0.11.5 or higher.

Overview

Affected versions of this package are vulnerable to Insufficiently Protected Credentials via the urls field in the layer descriptor. An attacker can obtain authentication credentials by serving a manifest with a urls entry pointing to an attacker-controlled host and causing the client to fall back to this URL, resulting in the credentials being sent to the external server. This is only exploitable if the registry server is malicious, the blob store is malicious, or the registry does not restrict external URLs for foreign blobs.

CVSS Base Scores

version 4.0
version 3.1