{"id":"GO-2026-6527","summary":"zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot","details":"zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion in zotregistry.dev/zot","aliases":["CVE-2026-61833","GHSA-qg67-7m6v-qg25"],"modified":"2026-09-28T17:00:17.504053852Z","published":"2026-09-28T16:43:40Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6527"},"references":[{"type":"ADVISORY","url":"https://github.com/project-zot/zot/security/advisories/GHSA-qg67-7m6v-qg25"},{"type":"WEB","url":"https://github.com/project-zot/zot/commit/7bb211bcd4352b90f3e99752607fbd1f050bf7ca"},{"type":"WEB","url":"https://github.com/project-zot/zot/pull/4161"},{"type":"WEB","url":"https://github.com/project-zot/zot/releases/tag/v2.1.18"}],"affected":[{"package":{"name":"zotregistry.dev/zot","ecosystem":"Go","purl":"pkg:golang/zotregistry.dev/zot"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6527.json"}},{"package":{"name":"zotregistry.dev/zot/v2","ecosystem":"Go","purl":"pkg:golang/zotregistry.dev/zot/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.18"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6527.json"}}],"schema_version":"1.9.0"}