Docker / Docker Desktop
30 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-17106 | Tar extraction in moby/go-archive can write outside the destination directory via link following | HIGH | 7.1 | Aug 18, 2026 |
| CVE-2026-8936 | Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM | HIGH | 8.2 | Jun 2, 2026 |
| CVE-2026-5843 | Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading | HIGH | 8.8 | May 22, 2026 |
| CVE-2026-5817 | Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends | HIGH | 8.8 | May 22, 2026 |
| CVE-2026-6406 | Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag | HIGH | 8.8 | May 22, 2026 |
| CVE-2026-2664 | Out of bounds read vulnerability in grpcfuse kernel module | MEDIUM | 6.8 | Feb 24, 2026 |
| CVE-2025-14740 | Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities | MEDIUM | 6.7 | Feb 4, 2026 |
| CVE-2025-13743 | Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs | LOW | 2.4 | Dec 9, 2025 |
| CVE-2025-9164 | Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows | HIGH | 8.8 | Oct 27, 2025 |
| CVE-2025-10657 | Docker Desktop with ECI Fails to Enforce Socket Command Restrictions | HIGH | 8.7 | Sep 26, 2025 |
| CVE-2025-9074 | Docker Desktop allows unauthenticated access to Docker Engine API from containers | CRITICAL | 9.3 | Aug 20, 2025 |
| CVE-2025-6587 | Exposure of system environment variables in Docker Desktop diagnostic logs | MEDIUM | 5.2 | Jul 3, 2025 |
| CVE-2025-3911 | Exposure in Docker Desktop logs of environment variables configured for running containers | MEDIUM | 5.2 | Apr 29, 2025 |
| CVE-2025-4095 | Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile | MEDIUM | 4.3 | Apr 29, 2025 |
| CVE-2025-3224 | Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion | HIGH | 7.3 | Apr 28, 2025 |
| CVE-2025-1696 | Exposure of Proxy Credentials in Docker Desktop Logs | MEDIUM | 5.2 | Mar 6, 2025 |
| CVE-2024-9348 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view | HIGH | 8.9 | Oct 16, 2024 |
| CVE-2024-8696 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop befo… | HIGH | 8.9 | Sep 12, 2024 |
| CVE-2024-8695 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.… | CRITICAL | 9.0 | Sep 12, 2024 |
| CVE-2024-6222 | In Docker Desktop before v4.29.0 an attacker who has gained access to the Docker Desktop VM through a container breakout can further escape to the host by pass… | HIGH | 7.3 | Jul 9, 2024 |
| CVE-2024-5652 | In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon co… | MEDIUM | 6.1 | Jul 9, 2024 |
| CVE-2023-0633 | In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPE | HIGH | 7.8 | Sep 25, 2023 |
| CVE-2023-0627 | Docker Desktop 4.11.x allows --no-windows-containers flag bypass | HIGH | 7.8 | Sep 25, 2023 |
| CVE-2023-0626 | Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route | CRITICAL | 9.8 | Sep 25, 2023 |
| CVE-2023-0625 | Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog | CRITICAL | 9.8 | Sep 25, 2023 |
Showing 1 to 25 of 30 CVEs