Junglewise Threat Intelligence

CVE-2026-33540: GO-2026-5094 - Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distributio

CVE-2026-33540 · Severity: low · CVSS 3.1 · Published 2026-06-25

Technologies: github.com/distribution/distribution (Go), github.com/distribution/distribution/v3 (Go). Vendors: Go.

Executive brief

Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distribution

Affected products

  • Go github.com/distribution/distribution
  • Go github.com/distribution/distribution/v3

Related threats