GPU VulnDB

Database/Container, Kubernetes & orchestration

JFrog Artifactory: authenticated write outside the Docker repository cache path

CVE-2026-66384Container, Kubernetes & orchestrationKnown exploitedcurated

Impact

Under specific remote-repository conditions an authenticated Artifactory user can write data outside the intended Docker cache path. The record describes an integrity-only primitive - no confidentiality or availability impact is claimed, and no code execution is asserted - but Artifactory is usually the registry a GPU fleet pulls its CUDA base images, driver container images and model-server images from, so an arbitrary-write primitive on the cache is a plausible step toward serving altered artifacts to every node that pulls. The CVE is KEV-flagged and the record links the OpenAI/Hugging Face incident technical report as a reference, so treat it as actively relevant rather than theoretical.

Who can reach it

An authenticated Artifactory user with network access to the instance who can drive a pull through an affected remote Docker repository. High attack complexity per the CVSS vector - the specific remote-repository conditions have to hold.

What to do

Upgrade Artifactory self-managed to a fixed release per the JFrog security advisories page; the record links the advisory index and release notes but does not name a fixed version, so read the advisory before scheduling. Rollout is an Artifactory service upgrade and restart, not fleet maintenance. Given the KEV flag, also audit recent writes under the Docker cache directory and re-verify the digests of base images your nodes have pulled.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.