Vulnerability Description
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/regclient/regclient/commit/7d17cff26c22196b5ddd66bda8c5ee4abf
- https://github.com/regclient/regclient/security/advisories/GHSA-qv35-3gw6-8q4j
FAQ
What is CVE-2025-24882?
CVE-2025-24882 is a vulnerability with a CVSS score of 5.2 (MEDIUM). regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
How severe is CVE-2025-24882?
CVE-2025-24882 has been rated MEDIUM with a CVSS base score of 5.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-24882?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.