Executive brief
The Model Context Protocol (MCP) Registry, which helps users discover and use AI-related server tools, contains a flaw in how it verifies ownership of container images. When the registry is busy or being intentionally flooded with requests, it may skip security checks that confirm a publisher actually owns the image they are listing. This allows an attacker to list reputable third-party software under their own name, potentially misleading users through impersonation or typo-squatting.
Technical details
The vulnerability exists in `internal/validators/registries/oci.go` where the `ValidateOCI` function returns `nil` (success) when a `http.StatusTooManyRequests` (429) error is received from an upstream OCI registry like Docker Hub. This 'fail-open' behavior bypasses the mandatory `io.modelcontextprotocol.server.name` label-match check, which is the primary mechanism for proving image ownership. An attacker can intentionally trigger this state by exhausting the registry's anonymous Docker Hub quota (100 pulls/6h) through rapid `/publish` requests. Once the quota is exhausted, the attacker can successfully publish a server record that points to any public OCI image they do not control. The issue is fixed in version 1.7.9 by treating rate limits as a validation error.
Affected products
- modelcontextprotocol registry < 1.7.9
Timeline
- 2026-05-09: other: Vulnerability identified in commit fe0cb3b
- 2026-05-12: disclosed: Reported via GitHub Private Security Advisory
- 2026-05-19: patched: Fix released in version 1.7.9
- 2026-05-19: advisory