๐Ÿ” CVE Alert

CVE-2026-31801

HIGH 7.7

zot create-only policy allows overwrite attempts of existing latest tag (update permission not required)

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0 to 2.1.14, zotโ€™s dist-spec authorization middleware infers the required action for PUT /v2/{name}/manifests/{reference} as create by default, and only switches to update when the tag already exists and reference != "latest". As a result, when latest already exists, a user who is allowed to create (but not allowed to update) can still pass the authorization check for an overwrite attempt of latest. This vulnerability is fixed in 2.1.15.

CWE CWE-863
Vendor project-zot
Product zot
Published Mar 10, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for project-zot zot

Be the first to know when new high vulnerabilities affecting project-zot zot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

project-zot / zot
>= 1.3.0, < v2.1.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/project-zot/zot/security/advisories/GHSA-85jx-fm8m-x8c6