Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.
History

Fri, 22 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-15
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 15 May 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:distribution:distribution:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Thu, 14 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 May 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Distribution
Distribution distribution
Vendors & Products Distribution
Distribution distribution

Thu, 14 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.
Title Distribution: Tag deletion bypasses `storage.delete.enabled` configuration
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-14T18:38:43.215Z

Reserved: 2026-04-22T15:11:54.671Z

Link: CVE-2026-41888

cve-icon Vulnrichment

Updated: 2026-05-14T18:38:37.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-14T18:16:47.380

Modified: 2026-05-15T18:25:48.043

Link: CVE-2026-41888

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-14T16:53:37Z

Links: CVE-2026-41888 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-22T02:00:13Z