Vulnerability GO-2026-6527
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 hours ago
September 28, 2026 at 04:43 PM UTC
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot
v0.2.6 - v1.4.3
v0.2.6 - v1.4.3
Summary
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot
Details
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
10 days ago
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion
v2.0.0-rc1 - v2.1.17 GHSA-qg67-7m6v-qg25
v2.0.0-rc1 - v2.1.17 GHSA-qg67-7m6v-qg25
Unknown
6 months ago
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot
v2.0.0-rc1 - v2.1.14 GO-2026-4668
v2.0.0-rc1 - v2.1.14 GO-2026-4668
Unknown
6 months ago
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot
v2.0.0-rc1 - v2.1.14 GO-2026-4668
v2.0.0-rc1 - v2.1.14 GO-2026-4668
High Risk
6 months ago
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required)
v2.0.0-rc1 - v2.1.14 GHSA-85jx-fm8m-x8c6
v2.0.0-rc1 - v2.1.14 GHSA-85jx-fm8m-x8c6
High Risk
6 months ago
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required)
v2.0.0-rc1 - v2.1.14 GHSA-85jx-fm8m-x8c6
v2.0.0-rc1 - v2.1.14 GHSA-85jx-fm8m-x8c6
Impacted packages
Timeline
Published
3 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:00 PM UTC