DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-7r53-fp7v-mm22

Package

gitlab-rails-ce-18.11

Component

github.com/distribution/distribution/v3

Latest update

Fixed

Fixed version

18.11.6-r0

Aliases

Severity

7.5

High

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-35172

Updates

Status

Fixed

Fixed version

18.11.6-r0

Status

Pending upstream fix

Impact

The github.com/distribution/distribution/v3 dependency at version v3.0.0-20221208165359-362910506bc2 contains a vulnerability that is fixed in v3.1.0. This is a transitive dependency brought in via github.com/devfile/library/v2/pkg/devfile (used by the gitlab-org/ruby/gems/devfile-gem that ships with GitLab) and cannot be directly overridden. Resolution requires:

  • Upstream github.com/devfile/library to migrate its imports from github.com/distribution/distribution/v3/reference to github.com/distribution/reference (the reference subpackage was extracted into its own module starting in distribution/v3 v3.1.0). Until that migration lands, go mod tidy cannot resolve the vulnerable transitive to v3.1.0+ because the upstream library still imports a path that no longer exists in the fixed version. Current blocker: upstream devfile/library has not migrated to github.com/distribution/reference. There is no v3 release that contains both the security fix and the /reference subpackage. See upstream project: https://github.com/devfile/library

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.