{"id":"GHSA-qhh4-458h-xwh2","summary":"@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry","details":"# Docker registry auth substring match forwards credentials to a different registry\n\n## Repository\n\n`cdxgen/cdxgen`\n\n## Affected product/package\n\n- Ecosystem: npm\n- Package: `@cyclonedx/cdxgen`\n- Reviewed tree version: `12.3.3`\n- Reviewed commit: `b1e179869fd7c6032c3d483c3f7bd4d7154ec22b`\n- Affected file: `lib/managers/docker.js`\n- Affected from: v9.9.5\n\nThe Single Executable Applications (SEA) binaries and container images are also affected.\n\n## Weakness\n\nCWE-522 / CWE-346.\n\n## Summary\n\nWhen cdxgen scans or pulls container images through the Docker daemon API, it builds an `X-Registry-Auth` header from Docker credentials in `DOCKER_CONFIG/config.json`. The credential selection logic matches configured registry keys with substring checks:\n\n```js\nif (forRegistry && !serverAddress.includes(forRegistry)) {\n  continue;\n}\n```\n\nThis is not an origin-safe registry comparison. For example, credentials configured for `private-registry.example.com` are selected for a requested image under `registry.example.com`, because:\n\n```js\n\"private-registry.example.com\".includes(\"registry.example.com\") === true\n```\n\nThe selected credentials are then serialized into `X-Registry-Auth` for the Docker API pull request targeting the requested registry.\n\n## Reproduction\n\nUse the attached/local proof:\n\n```sh\nnode submissions/github-gsa/cdxgen-docker-registry-auth-substring-forwarding/evidence/cdxgen_docker_registry_auth_substring_probe.mjs\n```\n\nThe proof is fully local. It creates a temporary Docker config containing credentials for `private-registry.example.com`, starts a localhost mock Docker API endpoint, sets `DOCKER_HOST` to that endpoint, then calls cdxgen's exported Docker request path for a pull from `registry.example.com`.\n\nObserved vulnerable output:\n\n```json\n{\n  \"decision\": \"GO\",\n  \"dockerConfigAuthHost\": \"private-registry.example.com\",\n  \"requestedRegistry\": \"registry.example.com\",\n  \"substringMatch\": true,\n  \"dockerApiUrl\": \"/images/create?fromImage=registry.example.com/team/app:latest\",\n  \"headerPresent\": true,\n  \"decodedHeader\": {\n    \"username\": \"trusted-user\",\n    \"password\": \"trusted-pass\",\n    \"serveraddress\": \"private-registry.example.com\"\n  }\n}\n```\n\n## Impact\n\nIf an operator has Docker credentials for a private registry and uses cdxgen to scan an image from a different registry whose hostname is a substring of that private registry hostname, cdxgen can attach the private registry credentials to the Docker pull request for the different registry.\n\nIn a realistic attack, an attacker who controls or can observe the requested registry can induce a victim to scan an image from that registry. The Docker daemon API receives an `X-Registry-Auth` payload containing credentials for the victim's private registry but associated with the attacker-requested pull. This is a credential forwarding/misbinding issue in cdxgen's container image handling.\n\n\n## References\n\nFunctions `normalizeRegistryHost` and `registriesMatch` added to normalize and perform strict host matching.\n\nFix PR: https://github.com/cdxgen/cdxgen/pull/3964\n\nResearcher: Francesco SabiuResearcher: Francesco Sabiu","modified":"2026-05-08T20:36:35.342191Z","published":"2026-05-08T20:06:00Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-05-08T20:06:00Z","nvd_published_at":null,"cwe_ids":["CWE-346","CWE-522"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/cdxgen/cdxgen/security/advisories/GHSA-qhh4-458h-xwh2"},{"type":"PACKAGE","url":"https://github.com/cdxgen/cdxgen"}],"affected":[{"package":{"name":"@cyclonedx/cdxgen","ecosystem":"npm","purl":"pkg:npm/%40cyclonedx/cdxgen"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.9.5"},{"fixed":"12.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qhh4-458h-xwh2/GHSA-qhh4-458h-xwh2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N"}]}