Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
History

Mon, 04 May 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple container
CPEs cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*
Vendors & Products Apple container

Sat, 02 May 2026 11:15:00 +0000

Type Values Removed Values Added
Title Credential Exposure via Hostname Bypass Patterns in Apple Container

Sat, 02 May 2026 08:30:00 +0000

Type Values Removed Values Added
Title Plaintext Exposure of Registry Credentials via Hostname Bypass in Apple Container
Weaknesses CWE-198
CWE-200

Fri, 01 May 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-522
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 May 2026 05:15:00 +0000

Type Values Removed Values Added
Title Plaintext Exposure of Registry Credentials via Hostname Bypass in Apple Container
Weaknesses CWE-198
CWE-200

Fri, 01 May 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Thu, 30 Apr 2026 22:30:00 +0000

Type Values Removed Values Added
Description Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2026-04-30T22:00:01.545Z

Updated: 2026-05-01T13:57:11.662Z

Reserved: 2026-03-03T16:36:03.984Z

Link: CVE-2026-28909

cve-icon Vulnrichment

Updated: 2026-05-01T13:55:30.552Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-30T23:16:20.437

Modified: 2026-05-04T18:22:48.623

Link: CVE-2026-28909

cve-icon Redhat

No data.