VulnSea

Docker has 12 CVEs on record between 2014 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was September 2026 with 3. The median CVSS is 7.8 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: Docker Sandboxes (2), docker_desktop (2), github.com/docker/distribution (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
4 prev 3

Products

  • Docker Sandboxes 2
  • docker_desktop 2
  • github.com/docker/distribution 2
  • github.com/docker/docker 2
  • docker 1
  • engine 1
12
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Docker vulnerabilities

CVEs affecting Docker, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-79994High· 8.7
1w ago

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlin…

TwilightDocker · Docker SandboxesEPSS 0.11%via NVD
CVE-2026-77179Critical· 9.4PoC
1w ago

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, an…

AbyssalDocker · Docker SandboxesEPSS 0.16%via NVD
CVE-2026-55887High· 8.7
1w ago

MCP Gateway allows easy and secure running and deployment of MCP servers

MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server stru…

Twilightdocker · mcp-gatewayEPSS 0.20%via NVD
CVE-2026-41568None
2mo ago

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files

Sunlitdocker · github.com/docker/dockerEPSS 0.11%via OSV
CVE-2026-5843High· 8.2PoC
4mo ago

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a mod…

Midnightdocker · docker_desktopEPSS 0.22%via NVD
CVE-2026-5817High· 8.2PoC
4mo ago

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import a…

Midnightdocker · docker_desktopEPSS 0.22%via NVD
CVE-2026-33997Medium· 6.8
5mo ago

Moby is an open source container framework

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…

Sunlitdocker · engineEPSS 0.39%via NVD
CVE-2021-41089Low· 2.8
2y ago

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

`docker cp` allows unexpected chmod of host files in Moby Docker Engine

Sunlitdocker · github.com/docker/dockerEPSS 0.29%via OSV
CVE-2021-41092Medium· 5.4
2y ago

Docker CLI leaks private registry credentials to registry-1.docker.io

Docker CLI leaks private registry credentials to registry-1.docker.io

Sunlitdocker · github.com/docker/cliEPSS 1.7%via OSV
GO-2022-0379None
4y ago

Type confusion in github.com/docker/distribution

Type confusion in github.com/docker/distribution

Sunlitdocker · github.com/docker/distributionvia OSV
GHSA-qq97-vm5h-rrhgLow· 3.0
4y ago

OCI Manifest Type Confusion Issue

OCI Manifest Type Confusion Issue

Sunlitdocker · github.com/docker/distributionvia OSV
CVE-2014-6407High· 7.5
11y ago

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

Twilightdocker · dockerEPSS 4.9%via NVD
Docker vulnerabilities (CVEs) · VulnSea