← All Advisories

CVE-2026-10517 Retracted by Red Hat Product Security and Upstream Clair/Claircore Maintainer After Confirming the Described PSK Authentication Behavior Is Intentional and Implemented in a Separate Package

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-10517

Key Details

CVECVE-2026-10517

What to Know

Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-10517
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-10517