Browse all 34 CVE security advisories affecting Docker. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Docker provides containerization software that enables developers to package applications and their dependencies into standardized units for consistent deployment across computing environments. Historically, vulnerabilities within the Docker ecosystem have frequently involved privilege escalation, allowing attackers to escape container isolation and gain root access on the host system. Other common flaw classes include remote code execution (RCE) and improper access controls within the daemon interface. With twenty-four CVEs currently on record, the platform has faced scrutiny regarding its default security configurations and the potential for lateral movement if a container is compromised. Notable incidents often stem from misconfigurations rather than inherent architectural failures, emphasizing the critical need for strict least-privilege principles and regular patching of the underlying engine to mitigate risks associated with shared kernel resources and exposed API endpoints.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-79994 | Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race — Docker Sandboxes CWE-367 | 8.7 | High | 2026-09-15 |
| CVE-2026-77179 | Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback — Docker Sandboxes CWE-59 | 9.4 | Critical | 2026-09-15 |
| CVE-2026-18171 | Docker Sandboxes read-only runtime mount writable through its shared-export alias — Docker Sandboxes CWE-863 | 5.7 | Medium | 2026-08-12 |
| CVE-2026-12539 | Docker Sandboxes ICMP egress restriction bypass after daemon restart — Docker Sandboxes CWE-923 | 5.1 | Medium | 2026-06-18 |
| CVE-2026-12039 | Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution — Docker Sandboxes CWE-923 | 5.7 | Medium | 2026-06-18 |
This page lists every published CVE security advisory associated with Docker. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.