GHSA-77vh-xpmg-72qhLow· 3.0▾ SunlitClarify `mediaType` handling
▾ Sunlit zone — Low / medium · no exploitation signal
impact 16.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
In the OCI Image Specification version 1.0.1 and prior, manifest and index documents are not self-describing and documents with a single digest could be interpreted as either a manifest or an index.
The Image Specification will be updated to recommend that both manifest and index documents contain a mediaType field to identify the type of document.
Release v1.0.2 includes these updates.
Software attempting to deserialize an ambiguous document may reject the document if it contains both “manifests” and “layers” fields or “manifests” and “config” fields.
https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m
If you have any questions or comments about this advisory:
github.com/opencontainers/image-spec < 1.0.2Upgrade to a patched release:
github.com/opencontainers/image-spec 1.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41190Low· 3.0Clarify Content-Type handling
CVE-2021-43784Medium· 6.0Overflow in netlink bytemsg length field allows attacker to override netlink-based container configuration in RunC
CVE-2021-30465High· 7.6mount destinations can be swapped via symlink-exchange to cause mounts outside the rootfs
CVE-2021-29136Medium· 5.5Improper input validation in umoci
CVE-2026-41579Medium· 3.3runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations