The mirror-registry application does not sanitize the host header in the HTTP request, allowing an attacker to perform a host header injection attack.