Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92542— Blind VXLAN injection into encrypted overlay networks from cluster peer

Quick assessment

Affected
Docker Docker Engine
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

防火墙规则在标记 VXLAN 数据报进行加密时,不加区分地同时匹配来自内核的真实 VXLAN 数据报以及由用户进程伪造的数据报。从 Linux Swarm 节点的主机网络命名空间发出的任何数据包,只要满足以下条件,都会使用覆盖网络的 IPsec 参数进行加密: 协议为 UDP 目标端口为 Swarm 数据路径端口 数据报以特定 VNI(VXLAN 网络标识符)的 VXLAN 头部开头,该 VNI 对应于节点上任何正在运行的容器所连接的已加密覆盖网络

CVSS 6.9 · Medium

Affected Version Matrix 5

VendorProduct Version RangeStatus
Docker Docker Engine < 25.0.19 affected
26.0.0< 29.8.2 affected
Docker Docker Engine overlay network driver < v25.0.19 affected
v26.0.0< * affected
Moby Moby overlay network driver v2.0.0-beta.0< v2.0.0-beta.25 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92542

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Blind VXLAN injection into encrypted overlay networks from cluster peer
Source: CVE Program / CVE List V5
Vulnerability Description
The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Docker Docker Engine 0 ~ 25.0.19 -
Docker Docker Engine overlay network driver 0 ~ v25.0.19 -
Moby Moby overlay network driver v2.0.0-beta.0 ~ v2.0.0-beta.25 -

II. Public POCs for CVE-2026-92542

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92542

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-92542 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92542

No comments yet


Leave a comment