Executive brief
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot
Affected products
- Go zotregistry.dev/zot
- Go zotregistry.dev/zot/v2
Junglewise Threat Intelligence
CVE-2026-31801 · Severity: low · CVSS 3.1 · Published 2026-03-12
Technologies: zotregistry.dev/zot (Go). Vendors: Go.
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot