Junglewise Threat Intelligence

CVE-2025-24976: GO-2025-3460 - Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution

CVE-2025-24976 · Severity: info · Published 2025-03-03

Technologies: github.com/distribution/distribution (Go). Vendors: Go.

Executive brief

Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution

Affected products

  • Go github.com/distribution/distribution

Related threats