GHSA-x2f5-332j-9xwq
MODERATECVE-2026-33990Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a model, Model Runner follows the realm URL from the registry's WWW-Authenticate header without validating the scheme, hostname, or IP range. A malicious OCI registry can set the realm to an internal URL (e.g., http://127.0.0.1:3000/), causing Model Runner running on the host to make arbitrary
- Affected
- < 1.1.25, >=0, <1.1.25
- Fixed in
- 1.1.25
- Weakness
- CWE-918
- Published
- 2026-03-30
- Source
- github