Skip to main content

Vendor archive

docker CVEs

Beta · best-effort

113 CVEs tagged to vendor docker19 Critical, 52 High, 37 Medium, 5 Low, 0 Unrated.

CVE-2026-5843

Published May 22, 2026

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5817

Published May 22, 2026

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This cause…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33990

Published Apr 1, 2026

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, Docker Model Runner contains an SSRF vulnerability in its OC…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-34040

Published Mar 31, 2026

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This…

CVSS 8.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-33997

Published Mar 31, 2026

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during dock…

CVSS 6.8 · Medium
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2025-15558

Published Mar 4, 2026

Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this dir…

CVSS 7.0 · High
evidence mentions
6
Buzz score
39.0
Vendor/product tagsBeta · best-effort

CVE-2026-2664

Published Feb 24, 2026

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local a…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13743

Published Dec 9, 2025

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in ex…

CVSS 2.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-64443

Published Dec 3, 2025

MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gateway runs in sse or streaming transport mode, it is vulnerabl…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3224

Published Apr 28, 2025

A vulnerability in the update process of Docker Desktop for Windows versions prior to 4.41.0 could allow a local, low-privileged attacker to escalate privileges to SYSTEM. During…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-8696

Published Sep 12, 2024

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8695

Published Sep 12, 2024

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5652

Published Jul 9, 2024

In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config option in Windo…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40453

Published Nov 7, 2023

Docker Machine through 0.16.2 allows an attacker, who has control of a worker node, to provide crafted version data, which might potentially trick an administrator into performing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5166

Published Sep 25, 2023

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5165

Published Sep 25, 2023

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time wi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0633

Published Sep 25, 2023

In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0627

Published Sep 25, 2023

Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0626

Published Sep 25, 2023

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0625

Published Sep 25, 2023

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38730

Published Apr 27, 2023

Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 113 CVEsPage 1 of 5