docker has 12 CVEs on record between 2022 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was September 2026 with 3. The median CVSS is 7.8 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/docker/docker (3), Docker Sandboxes (2), docker_desktop (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 3
Products
- github.com/docker/docker 3
- Docker Sandboxes 2
- docker_desktop 2
- github.com/docker/distribution 2
- engine 1
- github.com/docker/cli 1
Worst active — by depth score
CVE-2026-77179Critical· 9.4On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path64CVE-2026-5843High· 8.2The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json57CVE-2026-5817High· 8.2The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing57CVE-2026-79994High· 8.7The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname48CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers48
docker vulnerabilities
CVEs affecting docker, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-79994High· 8.7The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlin…
CVE-2026-77179Critical· 9.4PoCOn macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, an…
CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server stru…
CVE-2026-41568NoneRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
Race condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
CVE-2026-5843High· 8.2PoCThe MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a mod…
CVE-2026-5817High· 8.2PoCThe vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import a…
CVE-2026-33997Medium· 6.8Moby is an open source container framework
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privile…
CVE-2021-41089Low· 2.8`docker cp` allows unexpected chmod of host files in Moby Docker Engine
`docker cp` allows unexpected chmod of host files in Moby Docker Engine
CVE-2021-41092Medium· 5.4Docker CLI leaks private registry credentials to registry-1.docker.io
Docker CLI leaks private registry credentials to registry-1.docker.io
GO-2022-0379NoneType confusion in github.com/docker/distribution
Type confusion in github.com/docker/distribution
CVE-2014-6407High· 7.3Arbitrary Code Execution in Docker
Arbitrary Code Execution in Docker
GHSA-qq97-vm5h-rrhgLow· 3.0OCI Manifest Type Confusion Issue
OCI Manifest Type Confusion Issue