#VU125340 Improper access control in distribution - CVE-2026-35172
Published: April 8, 2026
distribution
Docker Inc.
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the repository-scoped redis blob descriptor cache invalidation logic when handling blob delete and subsequent stat or get operations across repositories. A remote attacker can request the same digest from another repository that still references it to disclose sensitive information.
Only deployments with both redis blob descriptor caching and delete enabled are vulnerable.