CVE-2026-105766: CWE-319 Cleartext Transmission of Sensitive Information in Chainguard Chainguard Academy (edu)
Description
CVE-2026-105766 is a low-severity vulnerability in Chainguard Academy (edu) involving cleartext transmission of sensitive information. The issue arises from the use of the $scheme variable in nginx.conf for trailing-slash directory redirects, which causes HTTPS requests for slashless directory paths to be redirected to HTTP URLs. This occurs because TLS terminates at the load balancer, and the redirect response uses HTTP, exposing content to on-path attackers. Browsers with HSTS preload support for the .dev domain are not affected, but clients without HSTS enforcement, such as command-line HTTP clients and scripts, are vulnerable.
CVSS v4.0
Score 2.3low
Affected software
Chainguard
Chainguard Academy (edu)
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Chainguard Academy (edu) stems from the backend use of the $scheme variable in nginx.conf's trailing-slash directory redirect configuration. When a client requests a directory path without a trailing slash over HTTPS, the server responds with a 301 redirect to the same path but with a trailing slash. However, because TLS terminates at the load balancer, the redirect Location header uses the $scheme variable, which results in an HTTP URL instead of HTTPS. This downgrade to plaintext HTTP allows an on-path network attacker to read or modify the redirected content. Clients enforcing HSTS for the .dev top-level domain are protected, but clients that do not enforce HSTS, including some command-line tools and scripts, remain vulnerable.
Potential Impact
An on-path attacker can intercept and modify documentation content served to clients following the redirect from HTTPS to HTTP. This could lead to exposure or tampering of sensitive information during the redirect process. The impact is limited by the fact that browsers with HSTS preload support for the .dev domain will not follow the insecure redirect, reducing the attack surface. However, non-browser clients without HSTS enforcement are susceptible to this downgrade attack.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. In the meantime, clients should ensure they enforce HSTS policies or avoid following redirects from HTTPS to HTTP. Vendors should update the nginx configuration to avoid using the $scheme variable in redirects when TLS terminates at a load balancer, ensuring redirects preserve HTTPS URLs.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- chainguard
- Date Reserved
- 2026-10-05T19:21:04.930Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac4063a2cdf04f65634e091
Added to database: 10/05/2026, 20:19:06 UTC
Last enriched: 10/05/2026, 20:33:33 UTC
Last updated: 10/05/2026, 20:34:04 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.