go package report

Is github.com/docker/model-runner safe?

1 known vulnerability, worst severity MODERATE.

cvss
9.1

how bad it is if exploited, out of 10

epss
0.30%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-x2f5-332j-9xwq, the advisory selected below

// advisories

GHSA-x2f5-332j-9xwq

MODERATECVE-2026-33990

Docker Model Runner contains an SSRF vulnerability in its OCI registry token exchange flow. When pulling a model, Model Runner follows the realm URL from the registry's WWW-Authenticate header without validating the scheme, hostname, or IP range. A malicious OCI registry can set the realm to an internal URL (e.g., http://127.0.0.1:3000/), causing Model Runner running on the host to make arbitrary

Affected
< 1.1.25, >=0, <1.1.25
Fixed in
1.1.25
Weakness
CWE-918
Published
2026-03-30
Source
github

GHSANVDMITREreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 01:28 UTC. The most recent advisory here was published 2026-03-30. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is github.com/docker/model-runner safe? go package security report | CyberXYZ