{"id":"CVE-2026-92543","title":"Docker Engine classifies a registry hostname as insecure using an any-match DNS check","summary":"Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and return…","severity":"high","cvss":7.6,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-295","CWE-319"],"vendor":"Docker","product":"Docker Engine","affected":["engine < 29.8.2","github.com/moby/moby/v2 < v2.0.0-beta.25"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:17:02.727","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92543","references":[{"url":"https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73","label":"security@docker.com"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T17:40:37.544Z","slug":"CVE-2026-92543","body":"## Overview\n\nDocker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}