Server-Side Request Forgery (SSRF) in distribution - CVE-2026-33540
Published: April 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery in pull-through cache proxy authentication when processing a WWW-Authenticate bearer realm from an upstream registry. A remote attacker can cause distribution to send configured upstream credentials via basic authentication to an attacker-controlled realm URL to disclose sensitive information.
This issue is exploitable if the configured upstream registry is attacker-controlled or if an attacker can intercept and modify the upstream connection.
Affected software
Fedora
docker-distribution
How to mitigate CVE-2026-33540
docker-distribution - update to 3.1.1-1.fc45