malcontent OCI image pull credential exfiltration via malicious registry token realm
Moderate severity
GitHub Reviewed
Published
Jan 29, 2026
in
chainguard-dev/malcontent
•
Updated Jan 31, 2026
Package
Affected versions
>= 0.10.0, < 1.20.3
Patched versions
1.20.3
Description
Published to the GitHub Advisory Database
Jan 29, 2026
Reviewed
Jan 29, 2026
Published by the National Vulnerability Database
Jan 29, 2026
Last updated
Jan 31, 2026
Malcontent could be made to expose Docker registry credentials if it scanned a specially crafted OCI image reference. Malcontent uses google/go-containerregistry for OCI image pulls, which by default uses the Docker credential keychain. A malicious registry could return a
WWW-Authenticateheader redirecting token authentication to an attacker-controlled endpoint, causing credentials to be sent to that endpoint.Fix: Default to anonymous auth for OCI pulls
Acknowledgements
Thank you to Oleh Konko from 1seal for discovering and reporting this issue.
References