{"id":"GO-2026-6225","summary":"Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env","details":"In github.com/chrismellard/docker-credential-acr-env/pkg/credhelper, the regular expression used by isACRRegistry to validate Azure Container Registry hostnames is unanchored. As a result, arbitrary hostnames containing the substring \".azurecr.io\" (such as evil.azurecr.io.attacker.com) are treated as valid ACR registries, causing ACRCredHelper.Get to send the Azure Active Directory (AAD) access token to attacker-controlled hosts.","modified":"2026-08-26T01:20:18.685370674Z","published":"2026-08-18T18:05:09Z","related":["CGA-rvv4-gfj5-24qv"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6225"},"references":[{"type":"REPORT","url":"https://github.com/chrismellard/docker-credential-acr-env/issues/21"},{"type":"WEB","url":"https://github.com/osscontainertools/docker-credential-acr"}],"affected":[{"package":{"name":"github.com/chrismellard/docker-credential-acr-env","ecosystem":"Go","purl":"pkg:golang/github.com/chrismellard/docker-credential-acr-env"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/chrismellard/docker-credential-acr-env/pkg/credhelper","symbols":["ACRCredHelper.Get","isACRRegistry"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6225.json"}}],"schema_version":"1.9.0","credits":[{"name":"Martin Zihlmann"}]}