CVE-2026-41888: Distribution's tag deletion bypasses `storage.delete.enabled` configuration
Tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41888 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →