Docker Model Runner SSRF - OCI Registry Realm Hijack Exposes Internal Network & Cloud Credentials
Docker Model Runner's OCI token exchange follows the WWW-Authenticate: realm URL without validating scheme, hostname, or IP range. A malicious registry sets …