Docker

Docker Desktop

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 18.08.2026 18:35:13
  • Zuletzt bearbeitet 19.08.2026 04:16:57

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using le...

  • EPSS 0.12%
  • Veröffentlicht 02.06.2026 21:09:03
  • Zuletzt bearbeitet 22.07.2026 19:10:00

Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76....

Medienbericht
  • EPSS 0.22%
  • Veröffentlicht 22.05.2026 19:28:38
  • Zuletzt bearbeitet 23.07.2026 11:10:00

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.j...

  • EPSS 0.22%
  • Veröffentlicht 22.05.2026 19:24:15
  • Zuletzt bearbeitet 23.07.2026 11:10:00

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute ar...

  • EPSS 0.21%
  • Veröffentlicht 22.05.2026 18:32:15
  • Zuletzt bearbeitet 23.07.2026 16:10:00

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. Howe...

  • EPSS 0.23%
  • Veröffentlicht 27.02.2026 21:06:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed ...

  • EPSS 0.19%
  • Veröffentlicht 24.02.2026 10:16:03
  • Zuletzt bearbeitet 27.02.2026 17:56:12

An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entri...

  • EPSS 0.2%
  • Veröffentlicht 04.02.2026 13:57:23
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verification, creati...

  • EPSS 0.21%
  • Veröffentlicht 09.12.2025 20:39:52
  • Zuletzt bearbeitet 30.01.2026 19:35:24

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.

  • EPSS 13.65%
  • Veröffentlicht 27.10.2025 20:37:32
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.fil...