CVE-2025-24976 - CVE House
Back to Database
Status published Medium CVE-2025-24976

Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT

Vulnerability Description

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a JSON web token (JWT). The issue lies in how the JSON web key (JWK) verification is performed. When a JWT contains a JWK header without a certificate chain, the code only checks if the KeyID (`kid`) matches one of the trusted keys, but doesn't verify that the actual key material matches. A fix for the issue is available at commit 5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd and expected to be a part of version 3.0.0-rc.3. There is no way to work around this issue without patching if the system requires token authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24976

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

distribution

View all reports →

Affected Software

distribution
Vulnerable Versions:
>= 3.0.0-beta.1, <= 3.0.0-rc.2

Timeline

Official Publish: February 11th, 2025
Last Modified: January 23rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)