CVE-2026-24845General(chainguard / malcontent)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a `WWW-Authenticate` header redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint. Version 1.20.3 fixes the issue by defaulting to anonymous auth for OCI pulls.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • malcontent

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
malcontent

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-01-30: 101-2901-30
Signal classification1 categories
General
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24845 Malcontent Docker Registry Credential Exposure via Malici... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24845 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-24845 with a reference to credential exposure in Docker Registry, but lacks any technical details, exploit code, or patch information.

    0000075
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24845 malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 0.10.0 and prior to version 1.20.3, malcontent co… https://www.cve.org/CVERecord?id=CVE-2026-24845

    Post summary

    The post merely references CVE-2026-24845, noting malcontent’s detection of supply‑chain compromises and linking to the CVE record, without providing additional technical, exploit, or patch details.

    00000209
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appchainguardmalcontent---

Explore more