Skip to content
VulniPulse

Docker Docker Engine / Moby Vulnerabilities & Security Advisories

10 advisories tracked · Docker Security (security@docker.com CNA) + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Docker advisory that VulniPulse classified as Docker Engine / Moby, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 5 high, 4 medium.

Android app · Google Play

Monitor Docker CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

Docker Security (security@docker.com CNA) + NVD

Docker Inc. is its own CVE Numbering Authority. VulniPulse ingests Docker's CVEs from the NVD CNA feed (security@docker.com) — Docker Desktop, Docker CLI, Docker Model Runner and Docker Sandboxes — and merges in the open-source engine components that publish under their own project CNAs (Moby, the Docker Engine upstream; BuildKit; containerd) via a subject-anchored NVD keyword feed that drops the heavy 'third-party app runs in a Docker Compose stack' noise. Docker Desktop / Engine is a near-universal part of every developer and homelab stack.

Latest Docker Docker Engine / Moby advisories

High7.6Docker Updated

High [CVE-2026-92543] Docker Engine classifies a registry hostname as insecure using an any-match DNS check

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection. Affected products named by the advisory: Moby.

CVE-2026-92543
Docker Engine / Moby
Oct 7, 2026
High7.1Docker

High [CVE-2026-17106] The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process. Affected products named by the advisory: Docker Sandboxes; Docker Desktop; Docker Engine; Docker CLI; and 1 more. Affected products named by the advisory: Docker Compose.

CVE-2026-17106
Docker DesktopDocker Engine / MobyBuildKit / ComposeDocker CLI / Scout
Aug 18, 2026
High7.2Docker

High [CVE-2026-42306] Docker Engine: Moby is an open source container framework

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

CVE-2026-42306
Docker Engine / Moby
Jun 12, 2026
High7.2Docker

High [CVE-2026-41567] Docker Engine: Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images Affected products named by the advisory: moby/v2/daemon; docker/daemon.

CVE-2026-41567
Docker Engine / Moby
Jun 5, 2026
High8.8Docker

High [CVE-2026-6406] The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the HostConfig. Mounts field rather than the HostConfig. Binds field. The ECI enforcement in the Docker Desktop API proxy only inspected Binds, allowing the mount to pass unchecked. This grants a container full access to the Docker Engine socket and, if the host user has logged in to container registries, their authentication credentials. A local attacker with the ability to run Docker CLI commands can exploit this to escape ECI restrictions, access the Docker Engine, and potentially escalate privileges.

CVE-2026-6406
Docker DesktopDocker Engine / MobyDocker CLI / Scout
May 22, 2026

← All Docker advisories