
CVE-2026-28909 Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed i… https://www.cve.org/CVERecord?id=CVE-2026-28909
Post summary
The post describes that connecting to malicious registries can expose credentials in plaintext, and notes that the vulnerability (CVE‑2026‑28909) has been fixed.

