Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12539— Docker Sandboxes ICMP egress restriction bypass after daemon restart

Quick assessment

Affected
Docker Docker Sandboxes
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docker Docker Sandboxes是美国Docker公司的一个容器沙箱隔离环境。 Docker Sandboxes 0.14.0版本至0.33.0之前版本存在安全漏洞,该漏洞源于在网络创建时仅应用授权器,在守护进程重启后未对从磁盘重建的网络重新应用授权,导致重启后持久化的沙箱可转发ICMP至任意主机,可能使沙箱内工作负载绕过ICMP出口限制,进行网络侦察并通过ICMP隐蔽通道泄露数据。

CVSS 5.1 · Medium EPSS 0.14% · P4

Affected Version Matrix 1

VendorProduct Version RangeStatus
Docker Docker Sandboxes 0.14.0< 0.33.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12539

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docker Sandboxes ICMP egress restriction bypass after daemon restart
Source: CVE Program / CVE List V5
Vulnerability Description
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlist.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通信信道对预期端点的不适当限制
Source: CVE Program / CVE List V5
Vulnerability Title
Docker Sandboxes 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Docker Docker Sandboxes是美国Docker公司的一个容器沙箱隔离环境。 Docker Sandboxes 0.14.0版本至0.33.0之前版本存在安全漏洞,该漏洞源于在网络创建时仅应用授权器,在守护进程重启后未对从磁盘重建的网络重新应用授权,导致重启后持久化的沙箱可转发ICMP至任意主机,可能使沙箱内工作负载绕过ICMP出口限制,进行网络侦察并通过ICMP隐蔽通道泄露数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Docker Docker Sandboxes 0.14.0 ~ 0.33.0 cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-12539

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12539

登录查看更多情报信息。

Vendor Pages for CVE-2026-12539 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12539

No comments yet


Leave a comment