CVE-2024-3727

Executive Summary

CVE-2024-3727 exposes a flaw in the containers/image library that allows attackers to trigger authenticated registry requests on behalf of a victim user, potentially causing resource exhaustion, local path traversal, and other privilege‑escalation attacks. The vulnerability is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.3 (HIGH) - Published: 2024-05-14T15:42:07.060 - Last Modified: 2026-08-21T18:16:44.683

Original Description: A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

"Simply put, you believer that things or people make you unhappy, but this is not accurate. You make yourself unhappy."

— Wayne Dyer
Source: NVD