CVE-2026-28400
- EPSS 0.02%
- Veröffentlicht 27.02.2026 21:06:12
- Zuletzt bearbeitet 02.03.2026 20:30:10
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 expose a POST `/engines/_configure` endpoint that accepts arbitrary runtime flags without authentication. These flags are passed ...
CVE-2026-2664
- EPSS 0.01%
- Veröffentlicht 24.02.2026 10:16:03
- Zuletzt bearbeitet 27.02.2026 17:56:12
An out of bounds read vulnerability in the grpcfuse kernel module present in the Linux VM in Docker Desktop for Windows, Linux and macOS up to version 4.61.0 could allow a local attacker to cause an unspecified impact by writing to /proc/docker entri...
CVE-2025-14740
- EPSS 0.01%
- Veröffentlicht 04.02.2026 13:57:23
- Zuletzt bearbeitet 04.02.2026 16:33:44
Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer creates this directory without proper ownership verification, creati...
CVE-2025-13743
- EPSS 0.04%
- Veröffentlicht 09.12.2025 20:39:52
- Zuletzt bearbeitet 30.01.2026 19:35:24
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.
CVE-2025-62725
- EPSS 0.03%
- Veröffentlicht 27.10.2025 20:37:32
- Zuletzt bearbeitet 30.10.2025 15:05:32
Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotations com.docker.compose.extends or com.docker.compose.envfile, Compose joins the attacker‑supplied value from com.docker.compose.fil...
CVE-2025-9164
- EPSS 0.03%
- Veröffentlicht 27.10.2025 13:53:40
- Zuletzt bearbeitet 30.10.2025 15:05:50
Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checking system directories, allowing local privilege escalation through mali...
CVE-2025-10657
- EPSS 0.02%
- Veröffentlicht 26.09.2025 21:15:34
- Zuletzt bearbeitet 29.09.2025 19:34:10
In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions feature https://doc...
CVE-2025-9074
- EPSS 0.9%
- Veröffentlicht 20.08.2025 13:28:35
- Zuletzt bearbeitet 25.09.2025 17:15:39
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Containe...
CVE-2025-6587
- EPSS 0.03%
- Veröffentlicht 03.07.2025 10:15:37
- Zuletzt bearbeitet 03.07.2025 15:13:53
System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to th...
CVE-2025-3911
- EPSS 0.1%
- Veröffentlicht 29.04.2025 17:20:34
- Zuletzt bearbeitet 02.05.2025 13:53:40
Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious actor with read access to these l...