zotregistry.dev/[email protected] has vulnerabilities — update to latest
Update to >= 2.1.15 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2024-39897 | Cache driver GetBlob() allows read access to any blob without access control check | 2.1.0 |
| high | CVE-2026-31801 | zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) | 2.1.15 |
| medium | CVE-2025-48374 | zot logs secrets | 1.4.4-0.20250522160828-8a99a3ed231f |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/zotregistry.dev/zotLast updated · 2022-11-30T07:35:06Z
| high |
| CVE-2025-23208 |
| Zot IdP group membership revocation ignored |
| 2.1.2 |
| unknown | CVE-2024-39897 | Cache driver GetBlob() allows read access to any blob without access control check in zotregistry.dev/zot | — |
| unknown | CVE-2025-23208 | Zot IdP group membership revocation ignored in zotregistry.dev/zot | — |
| unknown | CVE-2025-48374 | zot logs secrets in zotregistry.dev/zot | 1.4.4-0.20250522160828-8a99a3ed231f |
| unknown | CVE-2026-31801 | zot’s create-only policy allows overwrite attempts of existing latest tag (update permission not required) in zotregistry.dev/zot | 2.1.15 |