CVE 5.9 MEDIUM

Improper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity Bypass_CVE-2026-33467

5.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise influence the contents served to a self-hosted registry, to substitute a tampered package without the integrity check failing closed.

Basic Information

ID CVE-2026-33467
Source elastic
Published Apr 28, 2026 at 21:15

Affected Product

Vendor Elastic
Product Elastic Package Registry
Version 0.1.0
Affected Versions Elastic Elastic Package Registry 0.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.