CVE-2021-41092Medium· 5.4▾ SunlitDocker CLI leaks private registry credentials to registry-1.docker.io
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
1.5% → 1.7%
A bug was found in the Docker CLI where running docker login my-private-registry.example.com with a misconfigured configuration file (typically ~/.docker/config.json) listing a credsStore or credHelpers that could not be executed would result in any provided credentials being sent to registry-1.docker.io rather than the intended private registry.
This bug has been fixed in Docker CLI 20.10.9. Users should update to this version as soon as possible.
Ensure that any configured credsStore or credHelpers entries in the configuration file reference an installed credential helper that is executable and on the PATH.
If you have any questions or comments about this advisory:
github.com/docker/cli < 20.10.9Upgrade to a patched release:
github.com/docker/cli 20.10.9Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41089Low· 2.8`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2026-41568NoneRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
GO-2022-0379NoneType confusion in github.com/docker/distribution
GHSA-qq97-vm5h-rrhgLow· 3.0OCI Manifest Type Confusion Issue
CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers
CVE-2026-79994High· 8.7The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname