docker
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting docker.
- CVE-2026-79994Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race
- CVE-2026-55887MCP Gateway: Argument injection via OCI image label YAML in Docker MCP Gateway
- CVE-2026-77179Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
- CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link following
- CVE-2026-18171Docker Sandboxes read-only runtime mount writable through its shared-export alias
- CVE-2026-12539Docker Sandboxes ICMP egress restriction bypass after daemon restart
- CVE-2026-12039Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution
- CVE-2026-42306Moby: Race condition in docker cp allows bind mount redirection to host path7.2
- CVE-2026-41568Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap6.1
- CVE-2026-41567Docker: `PUT /containers/{id}/archive` executes container binary on the host7.2
- CVE-2026-8936Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM
- CVE-2026-5843Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading8.2
- CVE-2026-5817Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends8.2
- CVE-2026-6406Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag8.8
- CVE-2026-33990Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF)9.1