Description
A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure via Malicious Token Redirect
Action: Apply Patch
AI Analysis

Impact

A remote attacker who controls a container registry can redirect a client’s token request to a server chosen by the attacker. This causes the client to send its registry credentials to the attacker’s host, enabling the attacker to obtain the victim’s authenticators and potentially access the registry or other protected resources. The flaw is an insecure redirect vulnerability and is classified as CWE-601.

Affected Systems

The vulnerability affects Apple containerization implementations prior to version 0.41.0. Any deployment of Apple containerization that allows a client to contact a registry that can be manipulated by an attacker is susceptible.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attacker must be able to control or influence the registry endpoint the client contacts, which typically requires remote access to the registry configuration or hosting environment. Successful exploitation would grant an attacker the victim’s registry credentials, leading to credential compromise and potential lateral movement.

Generated by OpenCVE AI on September 17, 2026 at 22:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Apple containerization to version 0.41.0 or later as the issue is fixed in that release.
  • Ensure that registration endpoints used by client configurations are strictly controlled and not exposed to untrusted entities.
  • If an update cannot be applied immediately, isolate affected clients and refrain from using external registries until remediation is performed.

Generated by OpenCVE AI on September 17, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Token redirect vulnerability exposes registry credentials

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple containerization
Vendors & Products Apple
Apple containerization

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 16 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0.
References

Subscriptions

Apple Containerization
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T13:05:53.780Z

Reserved: 2026-07-22T00:46:44.572Z

Link: CVE-2026-65388

cve-icon Vulnrichment

Updated: 2026-09-17T13:04:51.439Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T23:16:54.147

Modified: 2026-09-18T17:48:19.003

Link: CVE-2026-65388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:00:13Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')