Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Distribution Version 3.1.2 behebt Sicherheitslücke CVE-2026-85747
Das Patch-Release v3.1.2 der Distribution-Registry behebt eine Sicherheitslücke (CVE-2026-85747), indem der Registry-Client Manifest- und Blob-Inhalte gegen den angefragten Digest prüft, aktualisiert sicherheitsrelevante Abhängigkeiten wie gRPC, OpenTelemetry und golang.org/x/crypto und korrigiert mehrere Fehler bei S3- und Azure-Speicher, Paginierung und Uploads.
Welcome to the v3.1.2 release of registry!
This is a stable release
This patch release includes security fixes, storage and pagination fixes, and dependency updates.
Please try out the release binaries and report any issues at https://github.com/distribution/distribution/issues.
Notable Changes
- Verify manifest and blob content against the requested digest in the registry client, protecting digest-pinned requests and pull-through caches (CVE-2026-85747 / GHSA-685w-q87j-wqw3).
- Update security-sensitive dependencies, including gRPC, OpenTelemetry, and golang.org/x/crypto (#4912, #4963, #4965, #4968). The OTLP gRPC log exporter now honors TLS certificates configured through environment variables.
- Fix S3 tag pagination and catalog listing when one name is a prefix of another (#4898, #4904), and return an empty tag array after the final pagination marker (#4931).
- Fix Azure blob type migration and a concurrent append-write race (#4871, #4888).
- Check the storage backend directly when writing blobs to avoid stale descriptor-cache entries (#4868).
- Reject malformed manifest digests and out-of-order final upload chunks correctly (#4945), accept unknown total sizes in Content-Range (#4892), and preserve upstream error codes (#4917).
- Stop the upload purger during registry shutdown (#4956).
- Validate S3 redirect endpoints at driver initialization (#4870). …