39 entries matching docker — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-58197 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too | HIGH | 8.8 | — | NVD | 2026-09-18 |
| CVE-2026-92762 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather | HIGH | 8.7 | 27%ile | NVD | 2026-09-16 |
| CVE-2026-85469 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docke | HIGH | 8.0 | 41%ile | NVD | 2026-09-16 |
| CVE-2026-92750 | Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticat | HIGH | 7.1 | 12%ile | NVD | 2026-09-16 |
| CVE-2026-61560 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (` | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-15 |
| CVE-2026-77179 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file | CRITICAL | 9.4 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-52824 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the pub | CRITICAL | 9.1 | 80%ile | NVD | 2026-09-15 |
| CVE-2026-55887 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway Y | HIGH | 8.7 | 10%ile | NVD | 2026-09-15 |
| CVE-2026-79994 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized work | HIGH | 8.7 | 1%ile | NVD | 2026-09-15 |
| CVE-2026-91936 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_di | HIGH | 8.3 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-53941 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | MEDIUM | 6.9 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-91942 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns u | MEDIUM | 5.1 | 13%ile | NVD | 2026-09-15 |
| CVE-2026-55630 | Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted | NONE | 0.0 | 25%ile | NVD | 2026-09-15 |
| CVE-2026-12944 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) | CRITICAL | 9.6 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-90938 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/p | HIGH | 8.8 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-82430 | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the ent | HIGH | 7.8 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-53717 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 52%ile | NVD | 2026-09-14 |
| CVE-2026-50025 | Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mous | MEDIUM | 6.9 | 8%ile | NVD | 2026-09-11 |
| CVE-2026-54248 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and | MEDIUM | 6.5 | 14%ile | NVD | 2026-09-11 |
| CVE-2026-56855 | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-78662 | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-84304 | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | HIGH | 7.5 | 35%ile | Microsoft | 2026-09-08 |
| CVE-2026-37236 | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override hea | MEDIUM | 5.3 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-17106 | Tar extraction in moby/go-archive can write outside the destination directory via link following | UNKNOWN | — | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-61711 | BuildKit: Custom frontend could bypass Seccomp/AppArmor | UNKNOWN | — | 29%ile | Microsoft | 2026-08-11 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-39832 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 47%ile | Microsoft | 2026-05-12 |
| CVE-2026-39833 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-46598 | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent | MEDIUM | 5.3 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-27141 | Sending certain HTTP/2 frames can cause a server to panic in golang.org/x/net | HIGH | 7.5 | 42%ile | Microsoft | 2026-02-10 |
| CVE-2014-0047 | Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage. | HIGH | 7.8 | 33%ile | Microsoft | 2017-10-10 |