Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Docker — Vulnerabilities & Security Advisories 34

Browse all 34 CVE security advisories affecting Docker. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Docker provides containerization software that enables developers to package applications and their dependencies into standardized units for consistent deployment across computing environments. Historically, vulnerabilities within the Docker ecosystem have frequently involved privilege escalation, allowing attackers to escape container isolation and gain root access on the host system. Other common flaw classes include remote code execution (RCE) and improper access controls within the daemon interface. With twenty-four CVEs currently on record, the platform has faced scrutiny regarding its default security configurations and the potential for lateral movement if a container is compromised. Notable incidents often stem from misconfigurations rather than inherent architectural failures, emphasizing the critical need for strict least-privilege principles and regular patching of the underlying engine to mitigate risks associated with shared kernel resources and exposed API endpoints.

CVE ID Title CVSS Severity Published
CVE-2026-79994 Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race — Docker Sandboxes CWE-367 8.7 High 2026-09-15
CVE-2026-55887 MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway — mcp-gateway CWE-88 8.7 High 2026-09-15
CVE-2026-77179 Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback — Docker Sandboxes CWE-59 9.4 Critical 2026-09-15
CVE-2026-18171 Docker Sandboxes read-only runtime mount writable through its shared-export alias — Docker Sandboxes CWE-863 5.7 Medium 2026-08-12
CVE-2026-12539 Docker Sandboxes ICMP egress restriction bypass after daemon restart — Docker Sandboxes CWE-923 5.1 Medium 2026-06-18
CVE-2026-12039 Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution — Docker Sandboxes CWE-923 5.7 Medium 2026-06-18
CVE-2026-8936 Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM — Docker Desktop CWE-674 - - 2026-06-02
CVE-2026-5843 Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading — Docker Desktop CWE-829 8.2 High 2026-05-22
CVE-2026-5817 Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends — Docker Desktop CWE-829 8.2 High 2026-05-22
CVE-2026-6406 Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag — Docker Desktop CWE-863 8.8 High 2026-05-22
CVE-2026-33990 Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF) — model-runner CWE-918 8.2AI High AI 2026-04-01
CVE-2025-15558 Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability — Docker CLI CWE-427 7.3 - 2026-03-04
CVE-2026-28400 Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint — model-runner CWE-749 7.6 High 2026-02-27
CVE-2026-2664 Out of bounds read vulnerability in grpcfuse kernel module — Docker Desktop CWE-125 7.1AI High AI 2026-02-24
CVE-2025-13743 Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs — Docker Desktop CWE-532 7.5AI High AI 2025-12-09
CVE-2025-64443 DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode — mcp-gateway CWE-749 8.3AI High AI 2025-12-03
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations — compose CWE-22 9.8AI Critical AI 2025-10-27
CVE-2025-9164 Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows — Docker Desktop CWE-427 7.8AI High AI 2025-10-27
CVE-2025-10657 Docker Desktop with ECI Fails to Enforce Socket Command Restrictions — Docker Desktop CWE-269 7.2 - 2025-09-26
CVE-2025-9074 Docker Desktop allows unauthenticated access to Docker Engine API from containers — Docker Desktop CWE-668 8.1AI High AI 2025-08-20
CVE-2025-6587 Exposure of system environment variables in Docker Desktop diagnostic logs — Docker Desktop CWE-532 6.5AI Medium AI 2025-07-03
CVE-2025-3911 Exposure in Docker Desktop logs of environment variables configured for running containers — Docker Desktop CWE-532 5.5AI Medium AI 2025-04-29
CVE-2025-4095 Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile — Docker Desktop CWE-862 6.1AI Medium AI 2025-04-29
CVE-2025-3224 Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion — Docker Desktop CWE-269 7.8AI High AI 2025-04-28
CVE-2025-0495 Secrets leakage to telemetry endpoint via cache backend configuration via buildx — buildx CWE-532 6.5 - 2025-03-17
CVE-2025-1696 Exposure of Proxy Credentials in Docker Desktop Logs — Docker Desktop CWE-532 4.3 - 2025-03-06
CVE-2024-9348 Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view — Docker Desktop CWE-20 9.8AI Critical AI 2024-10-16
CVE-2024-8696 A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. — Docker Desktop CWE-79 8.8AI High AI 2024-09-12
CVE-2024-8695 A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. — Docker Desktop CWE-79 9.8AI Critical AI 2024-09-12
CVE-2023-1802 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed — Docker Desktop CWE-319 5.9 Medium 2023-04-06

This page lists every published CVE security advisory associated with Docker. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.