Junglewise Threat Intelligence

CVE-2026-45781: Model Context Protocol Registry ownership bypass in OCI validator

CVE-2026-45781 · Severity: low · CVSS 3.5 · Published 2026-05-14

Technologies: github.com/modelcontextprotocol/registry (Go), Modelcontextprotocol Registry. Vendors: Model Context Protocol, Go.

Executive brief

The Model Context Protocol (MCP) Registry, which helps users discover and use AI-related server tools, contains a flaw in how it verifies ownership of container images. When the registry is busy or being intentionally flooded with requests, it may skip security checks that confirm a publisher actually owns the image they are listing. This allows an attacker to list reputable third-party software under their own name, potentially misleading users through impersonation or typo-squatting.

Technical details

The vulnerability exists in `internal/validators/registries/oci.go` where the `ValidateOCI` function returns `nil` (success) when a `http.StatusTooManyRequests` (429) error is received from an upstream OCI registry like Docker Hub. This 'fail-open' behavior bypasses the mandatory `io.modelcontextprotocol.server.name` label-match check, which is the primary mechanism for proving image ownership. An attacker can intentionally trigger this state by exhausting the registry's anonymous Docker Hub quota (100 pulls/6h) through rapid `/publish` requests. Once the quota is exhausted, the attacker can successfully publish a server record that points to any public OCI image they do not control. The issue is fixed in version 1.7.9 by treating rate limits as a validation error.

Affected products

  • modelcontextprotocol registry < 1.7.9

Timeline

  • 2026-05-09: other: Vulnerability identified in commit fe0cb3b
  • 2026-05-12: disclosed: Reported via GitHub Private Security Advisory
  • 2026-05-19: patched: Fix released in version 1.7.9
  • 2026-05-19: advisory

References

Related threats