regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
CVE ID: CVE-2025-24882
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.2
Vendor: regclient
Product: regclient
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.77% (scored less or equal to compared to others)
EPSS Date: 2025-02-28 (when was this score calculated)