#VU125341 Server-Side Request Forgery (SSRF) in distribution - CVE-2026-33540
Published: April 8, 2026
distribution
Docker Inc.
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery in pull-through cache proxy authentication when processing a WWW-Authenticate bearer realm from an upstream registry. A remote attacker can cause distribution to send configured upstream credentials via basic authentication to an attacker-controlled realm URL to disclose sensitive information.
This issue is exploitable if the configured upstream registry is attacker-controlled or if an attacker can intercept and modify the upstream connection.