Junglewise Threat Intelligence

CVE-2026-31801: GO-2026-4668 - zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot

CVE-2026-31801 · Severity: low · CVSS 3.1 · Published 2026-03-12

Technologies: zotregistry.dev/zot (Go). Vendors: Go.

Executive brief

zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot

Affected products

  • Go zotregistry.dev/zot
  • Go zotregistry.dev/zot/v2

Related threats