« Volver al listado

Docker

Docker Desktop: vulnerabilidades y CVE

Docker Desktop tiene 22 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE22
Últimos 12 meses5
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-73218Alta (7.7)0.63%—11 ago 2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a…
CVE-2026-5843Alta (8.8)0.18%—22 may 2026
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in…
CVE-2026-5817Alta (8.8)0.18%—22 may 2026
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes…
CVE-2026-6406Alta (8.8)0.20%—22 may 2026
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the…
CVE-2025-13743Baja (2.4)0.21%—9 dic 2025
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when…
CVE-2025-10657Alta (8.7)0.14%—26 sept 2025
In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command…
CVE-2025-4095Media (4.3)0.15%—29 abr 2025
Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization…
CVE-2025-3911Media (5.2)0.17%—29 abr 2025
Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious…
CVE-2023-5166Media (6.5)0.79%—25 sept 2023
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.
CVE-2023-5165Alta (8.8)0.33%—25 sept 2023
Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The…
CVE-2023-0633Alta (7.8)0.39%—25 sept 2023
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.
CVE-2023-0627Alta (7.8)0.27%—25 sept 2023
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.
CVE-2023-0626Crítica (9.8)0.87%—25 sept 2023
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.
CVE-2023-0625Crítica (9.8)0.87%—25 sept 2023
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
CVE-2023-0629Alta (7.1)0.22%—13 mar 2023
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via…
CVE-2023-0628Alta (7.8)0.27%—13 mar 2023
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
CVE-2021-44719Alta (8.4)0.27%—25 may 2022
Docker Desktop 4.3.0 has Incorrect Access Control.
CVE-2022-26659Alta (7.1)0.43%—25 mar 2022
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from…
CVE-2022-23774Media (5.3)0.93%—1 feb 2022
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
CVE-2021-45449Media (5.5)0.43%—12 ene 2022
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and…
CVE-2020-15360Alta (7.8)0.68%—27 jun 2020
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
CVE-2020-11492Alta (7.8)1.0%—5 jun 2020
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from…

Otros productos de Docker