Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18171— Docker Sandboxes read-only runtime mount writable through its shared-export alias

CVSS 5.7 · Medium EPSS 0.10% · P1

Possible ATT&CK Techniques 1AI

T1135 · Network Share Discovery

Affected Version Matrix 1

VendorProductVersion RangeStatus
DockerDocker Sandboxes0.35.0≤ 0.38.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18171

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docker Sandboxes read-only runtime mount writable through its shared-export alias
Source: CVE Program / CVE List V5
Vulnerability Description
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5
Vulnerability Title
Docker Sandboxes 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Docker Sandboxes是美国Docker公司的一个容器沙箱隔离环境。 Docker Sandboxes 0.35.0版本至0.38.0版本存在授权问题漏洞,该漏洞源于仅将运行时主机挂载的只读意图应用于客户机容器绑定,底层virtio-fs主机边缘授权被添加到沙箱策略共享允许列表且未设置访问模式,可能导致沙箱内非特权代码向只读挂载的主机目录写入数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
DockerDocker Sandboxes 0.35.0 ~ 0.38.0 cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-18171

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18171

登录查看更多情报信息。

Vendor Pages for CVE-2026-18171 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18171

No comments yet


Leave a comment