Junglewise Threat Intelligence
CVE-2026-33540: GO-2026-5094 - Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distributio
CVE-2026-33540 · Severity: low · CVSS 3.1 · Published 2026-06-25
Technologies: github.com/distribution/distribution (Go), github.com/distribution/distribution/v3 (Go). Vendors: Go.
Executive brief
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm in github.com/distribution/distribution
Affected products
- Go github.com/distribution/distribution
- Go github.com/distribution/distribution/v3