Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply substituted content with forged CRC32 corrections that passes per-piece checks, poisoning the cache with attacker-chosen container image layers or manifests that are re-seeded and executed by other hosts. | |
| Title | Kraken Agents Peer-to-Peer Download Cache Poisoning via Digest Verification Bypass | |
| First Time appeared |
Uber
Uber kraken |
|
| Weaknesses | CWE-354 | |
| CPEs | cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Uber
Uber kraken |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T19:06:15.419Z
Reserved: 2026-08-18T01:03:25.540Z
Link: CVE-2026-75625
Updated: 2026-08-18T19:05:52.811Z
Status : Received
Published: 2026-08-18T18:19:34.343
Modified: 2026-08-18T18:19:34.343
Link: CVE-2026-75625
No data.
OpenCVE Enrichment
No data.
-
CWE-354
Improper Validation of Integrity Check Value