Skip to main content

Vendor/product archive

docker / docker_desktop CVEs

Beta · best-effort

18 CVEs tagged to docker / docker_desktop0 Critical, 13 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2026-5843

Published May 22, 2026

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5817

Published May 22, 2026

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This cause…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13743

Published Dec 9, 2025

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in ex…

CVSS 2.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5166

Published Sep 25, 2023

Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-5165

Published Sep 25, 2023

Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time wi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0633

Published Sep 25, 2023

In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0627

Published Sep 25, 2023

Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0626

Published Sep 25, 2023

Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0625

Published Sep 25, 2023

Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0629

Published Mar 13, 2023

Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pip…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0628

Published Mar 13, 2023

Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted mali…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26659

Published Mar 25, 2022

Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45449

Published Jan 12, 2022

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15360

Published Jun 27, 2020

com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11492

Published Jun 5, 2020

An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker c…

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1