Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-92543

CVE-2026-92543: 2 tracked advisory records across Docker, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Docker

1 advisory
  • Advisory severityHigh7.6

    High [CVE-2026-92543] Docker Engine classifies a registry hostname as insecure using an any-match DNS check

    CVE-2026-92543Source published Source updated

    Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection. Affected products named by the advisory: Moby.

    Affected products in this advisory
    • Docker Engine
    • Moby
    Source-reported affected versions
    • Docker Engine before 29.8.2
    • Moby before v2.0.0-beta.25
    Source-reported fixed versions
    • 29.8.2
    • v2.0.0-beta.25
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Red Hat

1 advisory
  • Advisory severityHigh7.4

    High [CVE-2026-92543] Certificate verification bypass via flawed registry DNS check

    CVE-2026-92543Source published Source updated

    Certificate verification bypass via flawed registry DNS check. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Affected products named by the advisory: Multicluster Engine for Kubernetes; Multicluster Global Hub; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Ceph Storage 5; and 6 more.

    Related products — impact not confirmed
    • Multicluster Engine for Kubernetes
    • Multicluster Global Hub
    • Red Hat Advanced Cluster Management for Kubernetes 2
    • Red Hat Ceph Storage 5

    6 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery