---
id: CVE-2026-92543
title: >-
  Docker Engine classifies a registry hostname as insecure using an any-match
  DNS check
summary: >-
  Docker Engine classifies a registry hostname as insecure using an any-match
  DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as
  insecure CIDRs by default. isCIDRMatch resolves all of the hostname's
  addresses and return…
severity: high
cvss: 7.6
cvssVector: 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-295
  - CWE-319
vendor: Docker
product: Docker Engine
affected:
  - engine < 29.8.2
  - github.com/moby/moby/v2 < v2.0.0-beta.25
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:17:02.727'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92543'
references:
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73'
    label: security@docker.com
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T17:40:37.544Z'
---

## Overview

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
