Vulnerabilities in Docker

36 results
Vexday analysis

Docker apresenta 24 vulnerabilidades conhecidas na base, com 2 classificadas como críticas, mas nenhuma sob ataque ativo documentado até o momento. A fraqueza dominante (CWE-532 - Log Information Disclosure) sugere exposição de dados sensíveis em logs, um risco operacional significativo. O ritmo de descobertas permanece relevante, com 6 CVEs publicadas nos últimos 90 dias, indicando superfície de ataque em evolução contínua.

CVE-2026-2664MEDIUMOut of bounds read vulnerability in grpcfuse kernel moduleEPSS 0.2%CVE-2026-5843HIGHDocker Model Runner container-to-host code execution via MLX-LM model_file importlib loadingEPSS 0.2%CVE-2026-5817HIGHDocker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backendsEPSS 0.2%CVE-2025-1696MEDIUMExposure of Proxy Credentials in Docker Desktop LogsEPSS 0.2%CVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%CVE-2026-28400HIGHDocker Model Runner Unauthenticated Runtime Flag Injection via _configure EndpointEPSS 0.2%CVE-2025-3911MEDIUMExposure in Docker Desktop logs of environment variables configured for running containersEPSS 0.2%CVE-2026-8936HIGHUnbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VMEPSS 0.1%CVE-2026-12039MEDIUMDocker Sandboxes network egress allowlist bypass via unfiltered DNS resolutionEPSS 0.1%CVE-2025-10657HIGHDocker Desktop with ECI Fails to Enforce Socket Command RestrictionsEPSS 0.1%CVE-2025-4095MEDIUMRegistry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profileEPSS 0.1%CVE-2026-18171MEDIUMDocker Sandboxes read-only runtime mount writable through its shared-export aliasEPSS 0.1%CVE-2026-12539MEDIUMDocker Sandboxes ICMP egress restriction bypass after daemon restartEPSS 0.1%CVE-2026-79994HIGHDocker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink raceEPSS 0.1%CVE-2025-6587MEDIUMExposure of system environment variables in Docker Desktop diagnostic logsEPSS 0.1%CVE-2025-9164HIGHMultiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for WindowsEPSS 0.1%