Base image poisoning

A FROM line is a trust decision. Builds that pull an unpinned base image by a mutable tag inherit whatever that tag points to at build time. An attacker poisons the base: typosquatting a public name close to a popular one, hijacking an abandoned namespace, or compromising a shared internal base image that many teams build on.

dockerfile
# Unpinned base: resolves to whatever :latest points to at build time
FROM company/base:latest
# Pinned by digest resists poisoning
FROM company/base@sha256:<digest>

Exploitation notes#

  • The leverage is fan-out: one poisoned shared base image compromises every downstream image and deployment that rebuilds.
  • Typosquats target common names (one character off, a different registry namespace) and rely on a typo in a Dockerfile or CI config.
  • Pinning by digest defeats tag mutation, so unpinned FROM lines are the targets to look for.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more