What is CVE-2026-49349?
CVE-2026-49349 is a vulnerability in regclient, a Docker and OCI Registry Client in Go. In versions prior to 0.11.5, registry credentials may be inadvertently leaked to external servers when interacting with a malicious registry or blob store. Users should upgrade to the patched version and ensure credentials are only used with trusted registries.
Azərbaycanca: CVE-2026-49349 Go dilində yazılmış regclient alətində aşkarlanmış boşluqdur. 0.11.5-dən əvvəlki versiyalarda, registry etimadnamələri xarici serverlərə sıza bilər. İstifadəçilər regclient-i ən son versiyaya yeniləməli və etimadnamələrin yalnız etibarlı registry-lərlə istifadə edildiyinə əmin olmalıdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What action should be taken to protect against CVE-2026-49349?
Users should upgrade regclient to the latest version (0.11.5 or later) and ensure registry credentials are only used with trusted registries.
What software is affected by CVE-2026-49349?
This vulnerability affects the regclient tool written in Go, in versions prior to 0.11.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.