CVE-2026-28909: Apple Container

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

Affected products

  • Apple Container: before 0.12.3 (fixed in 0.12.3)

Published 2026-04-30. Last modified 2026-06-17.