Junglewise Threat Intelligence

CVE-2026-35172: Distribution stale blob access resurrection in Redis cache backend

CVE-2026-35172 · Severity: high · CVSS 7.5 · Published 2026-04-06

Technologies: Red Hat OpenShift Container Platform, github.com/distribution/distribution (Go), github.com/distribution/distribution/v3 (Go). Vendors: Red Hat, Go.

Executive brief

Distribution, a toolkit used to manage and store container images, contains a flaw that can restore access to data after it has been deleted. In specific configurations using Redis for caching, a deleted file may become accessible again if another user or repository accesses the same content. This could lead to the unauthorized exposure of sensitive container data that was intended to be removed.

Technical details

An improper access control vulnerability exists in Distribution's Redis cache backend. When a blob is deleted from a repository, the `repositoryScopedRedisBlobDescriptorService.Clear` function removes the shared digest descriptor but fails to invalidate the repo-scoped membership set in Redis. If a peer repository subsequently performs a `Stat` or `Get` on the same digest, the shared descriptor is repopulated. Because the original repository still contains the stale membership entry in Redis, it incorrectly trusts the new shared descriptor, effectively resurrecting read access to the deleted blob. This affects versions prior to 3.1.0 when `storage.cache.blobdescriptor` is set to `redis` and `storage.delete.enabled` is true.

Affected products

  • Distribution (formerly Docker Distribution) Distribution < 3.1.0
  • Red Hat OpenShift Container Platform 4.12, 4.13, 4.15, 4.16

Timeline

  • 2026-04-06: advisory: Initial advisory published by GitHub/Distribution maintainers
  • 2026-04-06: disclosed
  • 2026-06-11: patched: Red Hat released patches for OpenShift 4.15
  • 2026-06-17: patched: Red Hat released patches for OpenShift 4.16

References

Related threats