Docker desktop
This hub aggregates every CVE we track for Docker desktop, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
40
CVEs tracked
3
Critical
22
High
1
In CISA KEV
Severity distribution
HIGH22MEDIUM9CRITICAL3
Monthly trend
1
0
0
0
0
1
3
0
0
1
1
1
1
0
1
0
2
0
0
3
1
0
1
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Docker desktop.
- CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link following
- CVE-2026-8936Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM
- CVE-2026-5843Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading8.2
- CVE-2026-5817Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends8.2
- CVE-2026-6406Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag8.8
- CVE-2026-2664Out of bounds read vulnerability in grpcfuse kernel module7.8
- CVE-2025-14740Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities6.7
- CVE-2025-13743Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs7.5
- CVE-2025-9164Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows7.8
- CVE-2025-10657Docker Desktop with ECI Fails to Enforce Socket Command Restrictions
- CVE-2025-9074Docker Desktop allows unauthenticated access to Docker Engine API from containers8.6
- CVE-2025-6587Exposure of system environment variables in Docker Desktop diagnostic logs6.5
- CVE-2025-3911Exposure in Docker Desktop logs of environment variables configured for running containers
- CVE-2025-4095Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile
- CVE-2025-3224Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion7.8
Product normalization is registry-driven with AI assist and human review. How it works