CVE-2024-3727
Executive Summary
CVE‑2024‑3727 exposes a flaw in the containers/image library that lets attackers force authenticated registry requests on behalf of a victim. The resulting unauthorized access can trigger resource exhaustion, local path traversal, and other exploitation vectors. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.3 (HIGH) - Published: 2024-05-14T15:42:07.060 - Last Modified: 2026-09-19T12:16:38.260
Original Description: A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.
"If we learn to open our hearts, anyone, including the people who drive us crazy, can be our teacher."
— Pema Chodron