zotregistry.dev/zot
Activity
- Latest release
- 3y ago
- Total releases
- 59
- Cadence
- ~10 days
- Last 12 months
- 0
Details
- First release
- Jun 27, 2019
| Version | Released | |
|---|---|---|
v1.4.3
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3
patch
Dependencies (55)
+ 47 more |
|
v1.4.3-rc9
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc9
pre
Dependencies (55)
+ 47 more |
|
v1.4.3-rc8
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc8
pre
Dependencies (55)
+ 47 more |
|
v1.4.3-rc7
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc7
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc6
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc6
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc5
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc5
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc4
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc4
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc3
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc3
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc2
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc2
pre
Dependencies (51)
+ 43 more |
|
v1.4.3-rc1
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.3-rc1
pre
Dependencies (51)
+ 43 more |
|
v1.4.2
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2
patch
Dependencies (51)
+ 43 more |
|
v1.4.2-rc6
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc6
pre
Dependencies (51)
+ 43 more |
|
v1.4.2-rc5
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc5
pre
Dependencies (51)
+ 43 more |
|
v1.4.2-rc4
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc4
pre
Dependencies (52)
+ 44 more |
|
v1.4.2-rc3
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc3
pre
Dependencies (52)
+ 44 more |
|
v1.4.2-rc2
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc2
pre
Dependencies (52)
+ 44 more |
|
v1.4.2-rc1
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.2-rc1
pre
Dependencies (52)
+ 44 more |
|
v1.4.1
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1
patch
Dependencies (52)
+ 44 more |
|
v1.4.1-rc6
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1-rc6
pre
Dependencies (52)
+ 44 more |
|
v1.4.1-rc5
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1-rc5
pre
Dependencies (52)
+ 44 more |
|
v1.4.1-rc2
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.1-rc2
pre
Dependencies (52)
+ 44 more |
|
v1.4.0-rc4
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc4
pre
Dependencies (52)
+ 44 more |
|
v1.4.0
minor
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (52)
+ 44 more |
|
v1.4.0-rc2
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc2
pre
Dependencies (52)
+ 44 more |
|
v1.4.0-rc1
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.4.0-rc1
pre
Dependencies (52)
+ 44 more |
|
v1.3.9
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.9
patch
Dependencies (52)
+ 44 more |
|
v1.3.8
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.8
patch
Dependencies (52)
+ 44 more |
|
v1.3.8-rc3
pre
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.8-rc3
pre
Dependencies (52)
+ 44 more |
|
v1.3.7
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.7
patch
Dependencies (49)
+ 41 more |
|
v1.3.5
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.5
patch
Dependencies (49)
+ 41 more |
|
v1.3.4
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.4
patch
Dependencies (48)
+ 40 more |
|
v1.3.2
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.2
patch
Dependencies (42)
+ 34 more |
|
v1.3.1
minor
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.3.1
minor
Dependencies (35)
+ 27 more |
|
v1.2.4
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (34)
+ 26 more |
|
v1.2.2
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (34)
+ 26 more |
|
v1.2.1
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (35)
+ 27 more |
|
v1.2.0
minor
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (35)
+ 27 more |
|
v1.1.14
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.14
patch
Dependencies (34)
+ 26 more |
|
v1.1.13
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.13
patch
Dependencies (34)
+ 26 more |
|
v1.1.12
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.12
patch
Dependencies (34)
+ 26 more |
|
v1.1.11
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.11
patch
Dependencies (34)
+ 26 more |
|
v1.1.10
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.10
patch
Dependencies (34)
+ 26 more |
|
v1.1.9
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.9
patch
Dependencies (33)
+ 25 more |
|
v1.1.8
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.8
patch
Dependencies (33)
+ 25 more |
|
v1.1.7
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.7
patch
Dependencies (29)
+ 21 more |
|
v1.1.5
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.5
patch
Dependencies (29)
+ 21 more |
|
v1.1.4
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.4
patch
Dependencies (29)
+ 21 more |
|
v1.1.3
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.3
patch
Dependencies (29)
+ 21 more |
|
v1.1.2
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.2
patch
Dependencies (28)
+ 20 more |
|
v1.1.1
patch
4 CVEs
CVE-2026-31801
GO-2026-4668
GHSA-85jx-fm8m-x8c6
Mar 12, 2026
zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: . References Updated Mar 23, 2026 · Source: OSV.dev
CVE-2025-48374
GO-2025-3705
GHSA-c37v-3c8w-crq8
May 27, 2025
zot logs secrets in zotregistry.dev/zot zot logs secrets in zotregistry.dev/zot Fixed in
1.4.4-0.20250522160828-8a99a3ed231f
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2025-23208
GO-2025-3409
GHSA-c9p4-xwr9-rfhx
Jan 28, 2025
Zot IdP group membership revocation ignored in zotregistry.dev/zot Zot IdP group membership revocation ignored in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.2. References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-39897
GO-2024-2979
GHSA-55r9-5mx9-qq7r
Jul 10, 2024
Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot. NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions. (If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.) The additional affected modules and versions are: zotregistry.dev/zot before v2.1.0; zotregistry.io/zot before v2.1.0. References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.1
patch
Dependencies (24)
+ 16 more |