{"id":"CVE-2026-28909","details":"Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.","aliases":["GHSA-m5rp-xcpf-r8m7"],"modified":"2026-07-15T06:09:51.312051Z","published":"2026-04-30T23:16:20.437Z","references":[{"type":"ADVISORY","url":"https://github.com/apple/container/security/advisories/GHSA-m5rp-xcpf-r8m7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apple/container","events":[{"introduced":"0"},{"fixed":"f9899013fd43dd058fdf89709eed0b0861bfd931"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.12.3"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*"}}],"versions":["0.12.2","0.12.1","0.12.0","0.11.0","0.10.0","0.9.0","0.8.0","0.7.1","0.7.0","0.6.0","0.5.0","0.4.1","0.4.0","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28909.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}