{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-10517","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"REJECTED","assignerShortName":"redhat","dateReserved":"2026-06-01T07:25:15.700Z","datePublished":"2026-06-01T07:56:09.156Z","dateUpdated":"2026-07-27T08:35:41.456Z","dateRejected":"2026-07-27T08:35:41.456Z"},"containers":{"cna":{"rejectedReasons":[{"lang":"en","value":"Retracted following review by Red Hat Product Security and confirmation from the upstream Clair/Claircore maintainer. This CVE misattributes the described behavior to github.com/quay/claircore: the authentication mechanism in question (optional PSK, HTTP endpoint /indexer/api/v1/index_report) is implemented entirely in github.com/quay/clair; no PSK-related code exists anywhere in claircore's codebase or git history. The unauthenticated indexer API is Clair's documented, intentional design, authentication is an opt-in deployment choice, not a code defect. No fix commit was found in claircore between the version recorded as the affected boundary (1.5.52) and the following release (1.5.53); intervening commits are unrelated dependency and feature changes, so the \"fixed in 1.5.52\" status is inaccurate."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-07-27T08:35:41.456Z"}}}}