VendorsZot Registryzotall versions
Vulnerabilities

Zot Registry zot

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-31801
zot create-only policy allows overwrite attempts of existing latest tag (update permission not required)
Published 2026-03-10 · Analyzed
7.7EPSS 0.003
CVE-2025-23208
IdP group membership revocation ignored in zot
Published 2025-01-17 · Analyzed
7.3EPSS 0.004
CVE-2024-39897
Cache driver GetBlob() allows read access to any blob without access control check
Published 2024-07-09 · Analyzed
4.3EPSS 0.003