Executive brief
Regclient, a tool for managing container images, contains a flaw that can leak sensitive login credentials to unauthorized third-party servers. This occurs when the tool attempts to download image data from an external link provided by a malicious or compromised container registry. An attacker could use these leaked credentials to gain unauthorized access to your private container registries and the sensitive software images stored within them.
Technical details
A credential leak vulnerability exists in regclient versions up to 0.11.4 due to insufficient protection of authentication headers during cross-domain requests. When regclient processes an OCI image manifest containing 'foreign blobs' (layers with external URLs), it may fail over to these external URLs if the primary registry request fails. If the external server requests authentication, regclient incorrectly sends the credentials intended for the original registry. An attacker can exploit this by hosting a malicious registry or manifest that points to an attacker-controlled blob store. This is classified as CWE-522 (Insufficiently Protected Credentials) and has been patched in version 0.11.5.
Affected products
- regclient regclient <= 0.11.4
Timeline
- 2026-05-25: disclosed: Advisory submitted
- 2026-05-26: patched: Fix released
- 2026-06-26: advisory: GitHub Advisory published