{"id":"CVE-2021-41092","aliases":["GHSA-99pg-grm5-qq3v","BIT-docker-cli-2021-41092","GO-2024-2912"],"title":"Docker CLI leaks private registry credentials to registry-1.docker.io","summary":"Docker CLI leaks private registry credentials to registry-1.docker.io","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N","vendor":"docker","product":"github.com/docker/cli","ecosystem":"go","affected":["github.com/docker/cli < 20.10.9"],"patched":["github.com/docker/cli 20.10.9"],"published":"2024-06-10","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-99pg-grm5-qq3v","references":[{"url":"https://github.com/docker/cli/security/advisories/GHSA-99pg-grm5-qq3v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41092"},{"url":"https://github.com/docker/cli/commit/893e52cf4ba4b048d72e99748e0f86b2767c6c6b"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-222547.pdf"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Q6G6I4W5COQE25QMC7FJY3I3PAYFBB"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNFADTCHHYWVM6W4NJ6CB4FNFM2VMBIB"}],"tags":["osv","go"],"epss":0.01652,"epssPercentile":0.75529,"ingestedAt":"2026-07-09T18:56:36.270Z","slug":"CVE-2021-41092","body":"## Overview\n\n## Impact\n\nA bug was found in the Docker CLI where running `docker login my-private-registry.example.com` with a misconfigured configuration file (typically `~/.docker/config.json`) listing a `credsStore` or `credHelpers` that could not be executed would result in any provided credentials being sent to `registry-1.docker.io` rather than the intended private registry.\n\n## Patches\n\nThis bug has been fixed in Docker CLI 20.10.9.  Users should update to this version as soon as possible.\n\n## Workarounds\n\nEnsure that any configured `credsStore` or `credHelpers` entries in the configuration file reference an installed credential helper that is executable and on the `PATH`.\n\n## For more information\n\nIf you have any questions or comments about this advisory:\n\n* [Open an issue](https://github.com/docker/cli/issues/new/choose)\n* Email us at security@docker.com if you think you’ve found a security bug\n\n## Affected packages\n\n- `github.com/docker/cli < 20.10.9`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/docker/cli 20.10.9`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}