Container Escape via Inference: Two Vulnerabilities in Docker Model Runner
CVE-2026-5817 · CVE-2026-5843

whoami
Software and Security Engineer, as well as an independent security researcher focusing on AI, cloud, and software security.
CVE-2026-5817 · CVE-2026-5843
Two inference-backend vulnerabilities let an unprivileged container execute code on the Docker Desktop host.
CVE-2026-7020
A malicious model registry can exfiltrate files readable by a vulnerable Ollama process through tensor digest path traversal.
CVE-2026-33990
A malicious registry can turn a model pull into internal-network requests and token theft.
DEF CON 34 · August 2026
Weaponizing OCI Registries for SSRF, Credential Theft, and Container Escapes
View presentation detailsCVE-2026-5817 · CVE-2026-5843
CVE-2026-7020
CVE-2026-5530
CVE-2026-33990
For research conversations or anything else, get in touch on LinkedIn.