Skip to content
VulniPulse

Docker Security Advisories & CVEs

21 advisories tracked · Docker Security (security@docker.com CNA) + NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Docker CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your Docker device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Docker's recent advisories.

Official source

Docker Security (security@docker.com CNA) + NVD

Docker Inc. is its own CVE Numbering Authority. VulniPulse ingests Docker's CVEs from the NVD CNA feed (security@docker.com) — Docker Desktop, Docker CLI, Docker Model Runner and Docker Sandboxes — and merges in the open-source engine components that publish under their own project CNAs (Moby, the Docker Engine upstream; BuildKit; containerd) via a subject-anchored NVD keyword feed that drops the heavy 'third-party app runs in a Docker Compose stack' noise. Docker Desktop / Engine is a near-universal part of every developer and homelab stack.

Latest Docker advisories

Medium5.9Docker Updated

Medium [CVE-2026-105452] Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy

Docker Sandboxes could forward a client-supplied credential alongside a credential injected by the host egress proxy. The proxy removed alternate credentials only when their values matched known sentinel values, so untrusted code in an authorized sandbox could supply an unrecognized credential in another supported authentication header. For affected upstream services, this could authenticate the request to an attacker-controlled account and expose data included in the request.

CVE-2026-105452
Docker Desktop
Oct 8, 2026
Medium5.9Docker Updated

Medium [CVE-2026-101998] Docker Sandboxes could fail open while masking credentials in protected proxy responses

Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read returned data together with an error, affected handlers could forward unmasked bytes. Code inside an authorized sandbox could use this to recover host-managed OAuth access and refresh tokens or a derived Anthropic API key intended to remain outside the sandbox.

CVE-2026-101998
Docker Desktop
Oct 8, 2026
Medium6.7Docker Updated

Medium [CVE-2026-105570] Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively

Docker Sandboxes compared OAuth token-endpoint hostnames case-sensitively when deciding whether to mask managed credential responses, while request routing treated DNS hostnames case-insensitively. Untrusted code inside a sandbox could use a case-variant hostname to reach the genuine provider endpoint while bypassing response masking. If a user completed the OAuth flow, the provider's access and refresh tokens could be returned unmasked to the sandbox, exposing host-managed credentials.

CVE-2026-105570
Docker Desktop
Oct 8, 2026
Medium6.9Docker Updated

Medium [CVE-2026-92542] Docker: The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to Affected product named by the advisory: Docker. Affected products named by the advisory: Docker Engine; Docker Engine overlay network driver; Moby overlay network driver.

CVE-2026-92542
Docker Engine / Moby
Oct 7, 2026
Medium6.9Docker

Medium [CVE-2026-93321] Docker: malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon

A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon. Affected product named by the advisory: Docker.

CVE-2026-93321
BuildKit / Compose
Oct 5, 2026
Medium5.8Docker

Medium [CVE-2026-93315] Docker: When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup

When proxy networking with CA injection is enabled, a build can modify its CA bundle before cleanup. This may cause cleanup to block, operate outside the build rootfs, or fail without failing the build. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.

CVE-2026-93315
BuildKit / Compose
Oct 5, 2026
Medium6.9Docker

Medium [CVE-2026-103433] Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs

Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation checks a different path representation. Users who run untrusted Bake definitions are affected.

CVE-2026-103433
BuildKit / Compose
Oct 5, 2026
Medium6.0Docker

Medium [CVE-2026-93326] Docker: build step for a Git source, crafted in a specific way, can bypass some policy validation rules

A build step for a Git source, crafted in a specific way, can bypass some policy validation rules. A malicious build definition can make the repository look like it is coming from a different remote URL than it really is when Git clone is happening. If policy is doing more stricter validation, for example based on commit SHA, commit data, or signatures, then all these validations still apply correctly. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.

CVE-2026-93326
BuildKit / Compose
Oct 5, 2026
Medium6.8Docker

Medium [CVE-2026-93323] The Dockerfile frontend loaded the Dockerfile and.dockerignore files of a build context into memory without a size limit

The Dockerfile frontend loaded the Dockerfile and.dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

CVE-2026-93323
BuildKit / Compose
Oct 5, 2026
Medium6.0Docker

Medium [CVE-2026-93320] BuildKit may be tricked into performing file actions with special file inodes where regular files are expected

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

CVE-2026-93320
BuildKit / Compose
Oct 5, 2026
Medium5.7Docker

Medium [CVE-2026-93319] malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic

A malicious external BuildKit frontend can send requests using the internal API that can create conditions for a data race that can cause the BuildKit daemon to panic.

CVE-2026-93319
BuildKit / Compose
Oct 5, 2026
Medium5.9Docker

Medium [CVE-2026-93317] Docker: unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest

An unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity. Affected product named by the advisory: Docker. Affected product named by the advisory: BuildKit.

CVE-2026-93317
BuildKit / Compose
Oct 5, 2026
Medium5.7Docker

Medium [CVE-2026-18171] Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode

Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox can derive that path and write to a host directory the operator attached read-only.

CVE-2026-18171
Docker Desktop
Aug 12, 2026
Medium6.0Docker

Medium [CVE-2026-15792] malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

CVE-2026-15792
BuildKit / Compose
Jul 21, 2026
Medium6.9Docker

Medium [CVE-2026-15789] custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory

A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

CVE-2026-15789
BuildKit / Compose
Jul 21, 2026
Medium5.6Docker

Medium [CVE-2026-15788] BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root

BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the BuildKit daemon process.

CVE-2026-15788
BuildKit / Compose
Jul 20, 2026
Medium5.3Docker

Medium [CVE-2026-47262] Docker Engine: containerd is an open-source container runtime

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or Kubernetes control-plane components. This issue has been fixed in versions 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2.

CVE-2026-47262
Docker Engine / Moby
Jul 1, 2026
Medium5.7Docker

Medium [CVE-2026-12539] Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts

Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlist.

CVE-2026-12539
Docker Desktop
Jun 18, 2026
Medium5.7Docker

Medium [CVE-2026-12039] Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy

Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy. A workload inside a sandbox, which the threat model treats as untrusted, can therefore encode data into DNS labels for an attacker-controlled domain and exfiltrate it through a DNS covert channel, bypassing the configured allowlist.

CVE-2026-12039
Docker Desktop
Jun 18, 2026
Medium6.1Docker

Medium [CVE-2026-41568] Docker Engine: Moby is an open source container framework

Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

CVE-2026-41568
Docker Engine / Moby
Jun 12, 2026

← All vendors