CVE-2026-41888

EUVD-2026-30341
Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
distributiondistribution
𝑥
< 3.1.1
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
helm
suse enterprise sap 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP7
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP7
3.21.0-150000.1.75.1
fixed
helm-bash-completion
suse enterprise sap 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP7
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP7
3.21.0-150000.1.75.1
fixed
helm-zsh-completion
suse enterprise sap 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise sap 15 SP7
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP4
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP5
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP6
3.21.0-150000.1.75.1
fixed
suse enterprise server 15 SP7
3.21.0-150000.1.75.1
fixed