Docker
Docker Desktop: vulnerabilidades y CVE
Docker Desktop tiene 22 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73218 | Alta (7.7) | 0.63% | — | 11 ago 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a… |
| CVE-2026-5843 | Alta (8.8) | 0.18% | — | 22 may 2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in… |
| CVE-2026-5817 | Alta (8.8) | 0.18% | — | 22 may 2026 | The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes… |
| CVE-2026-6406 | Alta (8.8) | 0.20% | — | 22 may 2026 | The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the… |
| CVE-2025-13743 | Baja (2.4) | 0.21% | — | 9 dic 2025 | Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when… |
| CVE-2025-10657 | Alta (8.7) | 0.14% | — | 26 sept 2025 | In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command… |
| CVE-2025-4095 | Media (4.3) | 0.15% | — | 29 abr 2025 | Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization… |
| CVE-2025-3911 | Media (5.2) | 0.17% | — | 29 abr 2025 | Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as api keys, passwords, etc. A malicious… |
| CVE-2023-5166 | Media (6.5) | 0.79% | — | 25 sept 2023 | Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0. |
| CVE-2023-5165 | Alta (8.8) | 0.33% | — | 25 sept 2023 | Docker Desktop before 4.23.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions via the debug shell which remains accessible for a short time window after launching Docker Desktop. The… |
| CVE-2023-0633 | Alta (7.8) | 0.39% | — | 25 sept 2023 | In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0. |
| CVE-2023-0627 | Alta (7.8) | 0.27% | — | 25 sept 2023 | Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X. |
| CVE-2023-0626 | Crítica (9.8) | 0.87% | — | 25 sept 2023 | Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0. |
| CVE-2023-0625 | Crítica (9.8) | 0.87% | — | 25 sept 2023 | Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0. |
| CVE-2023-0629 | Alta (7.1) | 0.22% | — | 13 mar 2023 | Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via… |
| CVE-2023-0628 | Alta (7.8) | 0.27% | — | 13 mar 2023 | Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL. |
| CVE-2021-44719 | Alta (8.4) | 0.27% | — | 25 may 2022 | Docker Desktop 4.3.0 has Incorrect Access Control. |
| CVE-2022-26659 | Alta (7.1) | 0.43% | — | 25 mar 2022 | Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from… |
| CVE-2022-23774 | Media (5.3) | 0.93% | — | 1 feb 2022 | Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. |
| CVE-2021-45449 | Media (5.5) | 0.43% | — | 12 ene 2022 | Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and… |
| CVE-2020-15360 | Alta (7.8) | 0.68% | — | 27 jun 2020 | com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification. |
| CVE-2020-11492 | Alta (7.8) | 1.0% | — | 5 jun 2020 | An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from… |