Apple containerization RegistryClient realm hijack CVE-2026-65388 (CVSS 7.5); credential disclosure
CVE-2026-65388 (GHSA-mx96-5vvg-x2mg; Apple/containerization Swift package) covers RegistryClient following the WWW-Authenticate realm without validating host or scheme. A remote attacker who controls a container registry can redirect the client’s token request to an attacker-chosen host and disclose the victim’s registry credentials. GitHub advisory severity Moderate; published on the advisory 30 August 2026; Tenable/NVD indexing lists CVE published ~16 September 2026 with CVSS 3.1 base 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). GHSA lists affected versions ≤ 0.41.0 and patched versions > 0.41.0; Tenable text says the issue is addressed in containerization 0.41.0 — confirm the exact fixed build against GHSA before closing. No public exploitation claim on the Tenable/GHSA material reviewed this pass. Australia relevance: Apple container tooling / Mac container workflows pulling from untrusted registries.
- Product
- Apple containerization (Swift package apple/containerization) RegistryClient
- Versions
- Affected: ≤ 0.41.0 per GHSA; patched: > 0.41.0 per GHSA (confirm build; Tenable cites 0.41.0)
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N- Exploited in Australia?
- unknown
- Patch to
- Upgrade apple/containerization to a GHSA-listed patched build (> 0.41.0); avoid pulling images/auth from untrusted registries until patched.
Primary: GitHub Advisory GHSA-mx96-5vvg-x2mg — apple/containerization (CVE-2026-65388) · Vendor: Apple containerization — GHSA-mx96-5vvg-x2mg · CVE: CVE-2026-65388 · Tenable — CVE-2026-65388 (CVSS 7.5 High)
