目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

docker 厂商漏洞列表 / CVE 中文分析 30

docker 厂商相关 30 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

Docker 是领先的容器化平台,核心用途为简化应用构建、分发与运行。其历史漏洞多涉及容器逃逸、权限提升及远程代码执行,常因配置不当或内核缺陷引发。近期收录的 24 条 CVE 显示其持续面临安全挑战。值得关注的是,Docker 通过集成安全扫描工具及支持镜像签名机制,强化供应链安全。尽管存在风险,其生态仍广泛依赖,用户需及时更新补丁以防范潜在威胁。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-12539 Docker Sandboxes ICMP egress restriction bypass after daemon restart — Docker SandboxesCWE-923--2026-06-18
CVE-2026-12039 Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution — Docker SandboxesCWE-923--2026-06-18
CVE-2026-8936 Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM — Docker DesktopCWE-674--2026-06-02
CVE-2026-5843 Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading — Docker DesktopCWE-829 8.2 High2026-05-22
CVE-2026-5817 Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends — Docker DesktopCWE-829 8.2 High2026-05-22
CVE-2026-6406 Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag — Docker DesktopCWE-863 8.8 High2026-05-22
CVE-2026-33990 Docker Model Runner OCI Registry Client Vulnerable to Server-Side Request Forgery (SSRF) — model-runnerCWE-918 8.2AIHighAI2026-04-01
CVE-2025-15558 Docker Desktop Docker Plugins Uncontrolled Search Path Element Local Privilege Escalation Vulnerability — Docker CLICWE-427 7.3 -2026-03-04
CVE-2026-28400 Docker Model Runner Unauthenticated Runtime Flag Injection via _configure Endpoint — model-runnerCWE-749 7.6 High2026-02-27
CVE-2026-2664 Out of bounds read vulnerability in grpcfuse kernel module — Docker DesktopCWE-125 7.1AIHighAI2026-02-24
CVE-2025-13743 Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs — Docker DesktopCWE-532 7.5AIHighAI2025-12-09
CVE-2025-64443 DNS Rebinding vulnerability present when running MCP Gateway in sse or streaming mode — mcp-gatewayCWE-749 8.3AIHighAI2025-12-03
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations — composeCWE-22 9.8AICriticalAI2025-10-27
CVE-2025-9164 Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows — Docker DesktopCWE-427 7.8AIHighAI2025-10-27
CVE-2025-10657 Docker Desktop with ECI Fails to Enforce Socket Command Restrictions — Docker DesktopCWE-269 7.2 -2025-09-26
CVE-2025-9074 Docker Desktop allows unauthenticated access to Docker Engine API from containers — Docker DesktopCWE-668 8.1AIHighAI2025-08-20
CVE-2025-6587 Exposure of system environment variables in Docker Desktop diagnostic logs — Docker DesktopCWE-532 6.5AIMediumAI2025-07-03
CVE-2025-3911 Exposure in Docker Desktop logs of environment variables configured for running containers — Docker DesktopCWE-532 5.5AIMediumAI2025-04-29
CVE-2025-4095 Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile — Docker DesktopCWE-862 6.1AIMediumAI2025-04-29
CVE-2025-3224 Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion — Docker DesktopCWE-269 7.8AIHighAI2025-04-28
CVE-2025-0495 Secrets leakage to telemetry endpoint via cache backend configuration via buildx — buildxCWE-532 6.5 -2025-03-17
CVE-2025-1696 Exposure of Proxy Credentials in Docker Desktop Logs — Docker DesktopCWE-532 4.3 -2025-03-06
CVE-2024-9348 Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view — Docker DesktopCWE-20 9.8AICriticalAI2024-10-16
CVE-2024-8696 A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. — Docker DesktopCWE-79 8.8AIHighAI2024-09-12
CVE-2024-8695 A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. — Docker DesktopCWE-79 9.8AICriticalAI2024-09-12
CVE-2023-1802 In Docker Desktop 4.17.x the Artifactory Integration falls back to sending registry credentials over plain HTTP if the HTTPS health check has failed — Docker DesktopCWE-319 5.9 Medium2023-04-06
CVE-2021-41092 Docker CLI leaks private registry credentials to registry-1.docker.io — cliCWE-200 5.4 Medium2021-10-04
CVE-2014-8179 Docker和Docker CS Engine 输入验证错误漏洞 — Docker Engine 7.5 -2019-12-04
CVE-2014-8178 Docker Engine和CS Docker Engine 输入验证错误漏洞 — Docker Engine 5.5 -2019-12-04
CVE-2019-1020014 docker-credential-helpers 资源管理错误漏洞 — docker-credential-helpers 5.5 -2019-07-29

本页汇总了 docker 厂商截至目前公开的全部 30 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。