Executive brief
Distribution is a toolkit used to store and deliver container images, commonly used in Docker registries. A flaw allows users to delete image tags even when the system administrator has explicitly disabled deletion in the configuration. This could lead to service disruptions or supply chain issues if critical image tags are removed from a registry that was intended to be immutable.
Technical details
An authorization bypass exists in Distribution's manifest handler. While digest-based manifest deletion correctly respects the 'storage.delete.enabled' configuration, the tag deletion path via 'DELETE /v2/<name>/manifests/<tag>' fails to consult this setting. Specifically, the 'DeleteManifest' function in 'registry/handlers/manifests.go' calls 'tagService.Untag()' directly, which interacts with the storage driver to remove the tag path without checking the 'registry.deleteEnabled' flag. This allows any network-reachable API client to remove tags from repositories. The issue is resolved in version 3.1.1.
Affected products
- Distribution Distribution (Docker Registry) < 3.1.1
Timeline
- 2026-05-01: advisory: GitHub Security Advisory published
- 2026-05-14: disclosed: CVE published to NVD