{"id":"CVE-2026-78122","title":"docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set","summary":"docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /cont…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-1220"],"vendor":"Tecnativa","product":"docker-socket-proxy","affected":["docker-socket-proxy <= 0.5.0"],"published":"2026-08-22","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:43:32.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78122","references":[{"url":"https://gist.github.com/nedlir/e4f52f88a757f02c67db1fd5dd70d732","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Tecnativa/docker-socket-proxy","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Tecnativa/docker-socket-proxy/blob/v0.5.0/haproxy.cfg#L49-L61","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Tecnativa/docker-socket-proxy/issues/182","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Tecnativa/docker-socket-proxy/pull/183","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/docker-socket-proxy-through-insufficient-access-control-granularity-exposes-container-filesystems","label":"disclosure@vulncheck.com"},{"url":"https://github.com/Tecnativa/docker-socket-proxy/issues/182","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available","cve.org"],"epss":0.00309,"epssPercentile":0.21085,"exploits":{"github":1,"githubRepos":["https://github.com/Legendile7/CVE-2026-78122-POC"],"checkedAt":"2026-09-24T20:52:15.413Z"},"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-08-26T17:55:36.477479Z"},"ingestedAt":"2026-09-24T15:45:56.698Z","slug":"CVE-2026-78122","body":"## Overview\n\ndocker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}