CVE-2026-10517EPSS p21.4%

CVE-2026-10517CVE-2026-10517

Description

Rejected reason: Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the "fixed in 1.5.52" status is inaccurate.

Scoring

EPSS0.29% probability of exploitation · percentile 21.4% · 2026-07-27T12:04:57Z
Last modified2026-07-27

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-10622
CVE
CVE-2026-32591
CVE
CVE-2026-4366
CVE
CVE-2026-6848
CVE
CVE-2026-11569
CVE
CVE-2026-34504
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.