CVE-2026-65388: A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. in Apple containerization
CVE-2026-65388 is a vulnerability in Apple's containerization software where a remote attacker controlling a container registry can redirect a client's token request to an attacker-controlled host, potentially exposing the victim's registry credentials. This issue is fixed in containerization version 0.41.0.
AI Analysis
Technical Summary
This vulnerability allows a remote attacker who controls a container registry to manipulate the client's token request, redirecting it to a host of the attacker's choice. As a result, the victim's registry credentials may be disclosed to the attacker-controlled host. The flaw affects Apple containerization versions prior to 0.41.0 and is resolved in version 0.41.0.
Potential Impact
An attacker controlling a container registry can cause a client to send sensitive authentication tokens to an attacker-controlled host, leading to credential disclosure. This could compromise the victim's access to container registries and potentially allow unauthorized actions using those credentials.
Mitigation Recommendations
Upgrade Apple containerization to version 0.41.0 or later, where this vulnerability is addressed. No other mitigation steps are indicated.
CVE-2026-65388: A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. in Apple containerization
Description
CVE-2026-65388 is a vulnerability in Apple's containerization software where a remote attacker controlling a container registry can redirect a client's token request to an attacker-controlled host, potentially exposing the victim's registry credentials. This issue is fixed in containerization version 0.41.0.
Affected software
Apple
containerization
pkg:github/apple/containerizationRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability allows a remote attacker who controls a container registry to manipulate the client's token request, redirecting it to a host of the attacker's choice. As a result, the victim's registry credentials may be disclosed to the attacker-controlled host. The flaw affects Apple containerization versions prior to 0.41.0 and is resolved in version 0.41.0.
Potential Impact
An attacker controlling a container registry can cause a client to send sensitive authentication tokens to an attacker-controlled host, leading to credential disclosure. This could compromise the victim's access to container registries and potentially allow unauthorized actions using those credentials.
Mitigation Recommendations
Upgrade Apple containerization to version 0.41.0 or later, where this vulnerability is addressed. No other mitigation steps are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apple
- Date Reserved
- 2026-07-22T00:46:44.572Z
- State
- PUBLISHED
Threat ID: 6aab18f055bf5e2cf53e7783
Added to database: 09/16/2026, 22:32:16 UTC
Last enriched: 09/16/2026, 22:47:07 UTC
Last updated: 09/16/2026, 22:47:07 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.