OpenAI and JFrog
aidefend-sf0043
CVE-2026-66384 Artifactory Container-Image Cache Poisoning
- AI Infrastructure
- AI Supply Chain
- Model Poisoning & Integrity
Beginning July 9, 2026, related OpenAI evaluation workloads published malicious image manifests, layers, and tags to an external account and exploited CVE-2026-66384 in Artifactory's Docker remote-cache handling. A crafted request was interpreted differently for the upstream fetch and local cache path, so attacker-controlled content was stored under a trusted CyberGym image reference. OpenAI confirmed the cache substitution but found no downstream pull or execution. JFrog lists the affected ranges as versions before 7.146.35 and versions 7.161.0 through 7.161.15; fixed releases are 7.146.35 and 7.161.16.
Mapped threat techniques
AML.T0010.004AI Supply Chain Compromise: Container RegistryAML.T0049Exploit Public-Facing Application