← Back to feed Search feed

Docker vulnerabilities

23 entries matching docker — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-69259Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite RecoCRITICAL9.4NVD2026-08-04
CVE-2026-69096OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend afterHIGH8.774%ileNVD2026-08-03
CVE-2026-52855Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{CRITICAL9.920%ileNVD2026-07-31
CVE-2026-16503Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces CRITICAL9.116%ileNVD2026-07-31
CVE-2026-67208Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execCRITICAL9.362%ileNVD2026-07-30
CVE-2026-47882When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud FounHIGH8.37%ileNVD2026-07-30
CVE-2026-47873The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network intHIGH8.08%ileNVD2026-07-30
CVE-2026-54574proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain taHIGH8.24%ileNVD2026-07-29
GHSA-vg6v-j97m-h5xq@novu/application-generic: `validateUrlSsrf` permits CGNAT (100.64.0.0/10) destinations — affects Workflow HTTP request MEDIUM6.8GitHub2026-07-28
CVE-2026-46595Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/sshCRITICAL10.040%ileMicrosoft2026-05-12
CVE-2026-39830Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshCRITICAL9.146%ileMicrosoft2026-05-12
CVE-2026-39831Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshCRITICAL9.135%ileMicrosoft2026-05-12
CVE-2026-39834Invoking infinite loop on large channel writes in golang.org/x/crypto/sshCRITICAL9.142%ileMicrosoft2026-05-12
CVE-2026-39833Invoking key constraints not enforced in golang.org/x/crypto/ssh/agentCRITICAL9.134%ileMicrosoft2026-05-12
CVE-2026-39832Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agentCRITICAL9.145%ileMicrosoft2026-05-12
CVE-2026-39829Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/sshHIGH7.538%ileMicrosoft2026-05-12
CVE-2026-46597Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshHIGH7.538%ileMicrosoft2026-05-12
CVE-2026-39827Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshMEDIUM6.520%ileMicrosoft2026-05-12
CVE-2026-39828Invoking bypass of certificate restrictions in golang.org/x/crypto/sshMEDIUM6.330%ileMicrosoft2026-05-12
CVE-2026-39835Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/sshMEDIUM5.340%ileMicrosoft2026-05-12
CVE-2026-46598Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agentMEDIUM5.334%ileMicrosoft2026-05-12
CVE-2026-39882OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodiesMEDIUM5.39%ileMicrosoft2026-04-14
CVE-2023-45288HTTP/2 CONTINUATION flood in net/httpHIGH7.5100%ileMicrosoft2024-04-09