CVE-2026-33990 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Docker Model Runner (DMR) versions prior to 1.1.25, software used for managing and deploying AI models. This flaw allows a malicious OCI registry to redirect DMR to internal URLs, enabling arbitrary GET requests to internal services and exfiltration of sensitive data back to the attacker. Rated 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N), it can be exploited remotely without authentication or user interaction, leading to high confidentiality and integrity impacts. The vulnerability is patched in version 1.1.25; while no public exploits are available and it's not in CISA's KEV catalog, it is listed as "Active" on a hot list, indicating high concern with limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.25CPE matchmatch criteria | cpe:2.3:a:docker:model_runner:*:*:*:*:*:docker:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.