CVE-2020-29591: Docker Registry

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.

Affected products

  • Docker Registry: version 2.5 only; version 2.5.0 only; version 2.5.1 only; version 2.6.0 only; version 2.6.1 only; version 2.7.0 only

Published 2020-12-11. Last modified 2026-06-17.