Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92543— Docker Engine insecure-registry fallback via malicious DNS responses

Quick assessment

Affected
Docker Docker Engine
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Docker Engine 在使用“任意匹配”的 DNS 检查机制时,将某个注册表主机名分类为“不安全”。默认情况下, 函数会将 和 注入为不安全的 CIDR 范围。 函数会解析该主机名的所有 IP 地址,只要其中任意一个地址落入上述不安全的 CIDR 列表,该函数即返回 。 然而,在建立连接时,Docker 的传输层会重新对主机名(而非与该主机名匹配的不安全 CIDR 中的特定 IP 地址)进行 DNS 解析和拨号。因此,如果 DNS 返回的结果集中包含一个本地回环地址(loopback IP)和一个非回环的、由

CVSS 7.6 · High

Possible ATT&CK Techniques 1 AI

T1071 · Application Layer Protocol

Affected Version Matrix 2

VendorProduct Version RangeStatus
Docker Docker Engine < 29.8.2 affected
Moby Moby < v2.0.0-beta.25 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92543

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Docker Engine insecure-registry fallback via malicious DNS responses
Source: CVE Program / CVE List V5
Vulnerability Description
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Docker Docker Engine 0 ~ 29.8.2 -
Moby Moby 0 ~ v2.0.0-beta.25 -

II. Public POCs for CVE-2026-92543

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92543

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-92543 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92543

No comments yet


Leave a comment