← Back to feed Search feed

Docker vulnerabilities

39 entries matching docker — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-58197ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to TooHIGH8.8NVD2026-09-18
CVE-2026-92762Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather HIGH8.727%ileNVD2026-09-16
CVE-2026-85469A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/dockeHIGH8.041%ileNVD2026-09-16
CVE-2026-92750Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticatHIGH7.112%ileNVD2026-09-16
CVE-2026-61560`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`CRITICAL9.852%ileNVD2026-09-15
CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked fileCRITICAL9.46%ileNVD2026-09-15
CVE-2026-52824Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pubCRITICAL9.180%ileNVD2026-09-15
CVE-2026-55887MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YHIGH8.710%ileNVD2026-09-15
CVE-2026-79994The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workHIGH8.71%ileNVD2026-09-15
CVE-2026-91936Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_diHIGH8.328%ileNVD2026-09-15
CVE-2026-53941Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiMEDIUM6.932%ileNVD2026-09-15
CVE-2026-91942crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns uMEDIUM5.113%ileNVD2026-09-15
CVE-2026-55630Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted NONE0.025%ileNVD2026-09-15
CVE-2026-12944IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) CRITICAL9.616%ileNVD2026-09-14
CVE-2026-90938LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/pHIGH8.828%ileNVD2026-09-14
CVE-2026-82430Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entHIGH7.84%ileNVD2026-09-14
CVE-2026-53717Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.552%ileNVD2026-09-14
CVE-2026-50025Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, MousMEDIUM6.98%ileNVD2026-09-11
CVE-2026-54248Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services andMEDIUM6.514%ileNVD2026-09-11
CVE-2026-56855Prevent DoS on deadlocked established channel in golang.org/x/crypto/sshHIGH7.532%ileMicrosoft2026-09-08
CVE-2026-78662Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/sshHIGH7.525%ileMicrosoft2026-09-08
CVE-2026-84304gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationHIGH7.535%ileMicrosoft2026-09-08
CVE-2026-37236grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override heaMEDIUM5.338%ileMicrosoft2026-08-11
CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link followingUNKNOWN26%ileMicrosoft2026-08-11
CVE-2026-61711BuildKit: Custom frontend could bypass Seccomp/AppArmorUNKNOWN29%ileMicrosoft2026-08-11
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.042%ileMicrosoft2026-05-12
CVE-2026-39830Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshCRITICAL9.148%ileMicrosoft2026-05-12
CVE-2026-39832Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentCRITICAL9.147%ileMicrosoft2026-05-12
CVE-2026-39833Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentCRITICAL9.135%ileMicrosoft2026-05-12
CVE-2026-39834Invoking infinite loop on large channel writes in golang.org/x/crypto/sshCRITICAL9.143%ileMicrosoft2026-05-12
CVE-2026-39831Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshCRITICAL9.136%ileMicrosoft2026-05-12
CVE-2026-39829Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/sshHIGH7.540%ileMicrosoft2026-05-12
CVE-2026-46597Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshHIGH7.540%ileMicrosoft2026-05-12
CVE-2026-39827Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshMEDIUM6.521%ileMicrosoft2026-05-12
CVE-2026-39828Invoking bypass of certificate restrictions in golang.org/x/crypto/sshMEDIUM6.331%ileMicrosoft2026-05-12
CVE-2026-39835Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/sshMEDIUM5.342%ileMicrosoft2026-05-12
CVE-2026-46598Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agentMEDIUM5.335%ileMicrosoft2026-05-12
CVE-2026-27141Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/netHIGH7.542%ileMicrosoft2026-02-10
CVE-2014-0047Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.HIGH7.833%ileMicrosoft2017-10-10