Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attackers to cause a denial of service (memory consumption) via the manifest endpoint.
github.com/docker/distribution/registry/storage github.com/docker/distribution/registry/handlers
{ "nvd_published_at": "2017-07-20T23:29:00Z", "cwe_ids": [ "CWE-770" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-02-07T00:04:08Z" }