GO-2026-6225
Dashboard / Vulnerabilities / GO-2026-6225
Summary: Credential leakage to untrusted hosts in github.com/chrismellard/docker-credential-acr-env
Details: In github.com/chrismellard/docker-credential-acr-env/pkg/credhelper, the regular expression used by isACRRegistry to validate Azure Container Registry hostnames is unanchored. As a result, arbitrary hostnames containing the substring ".azurecr.io" (such as evil.azurecr.io.attacker.com) are treated as valid ACR registries, causing ACRCredHelper.Get to send the Azure Active Directory (AAD) access token to attacker-controlled hosts.
References: https://github.com/chrismellard/docker-credential-acr-env/issues/21, https://github.com/osscontainertools/docker-credential-acr
Affected packages
Package
Name: github.com/chrismellard/docker-credential-acr-env
Purl: pkg:golang/github.com/chrismellard/docker-credential-acr-env
Affected ranges
Type: SEMVER
Events:
