Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
227 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.42% | — | Psyb0t Docker MailboxAI | 29/9/2026 | 29/9/2026 | Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or… | |
| Pendiente de análisis | Alta (8) | 0.52% | — | Noelware Docker-manifest-actionAIQuay Builder-qemuAI | 16/9/2026 | 18/9/2026 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials… | |
| Pendiente de análisis | Alta (8.7) | 0.14% | — | Docker SandboxesAI | 15/9/2026 | 16/9/2026 | The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary… | |
| Aplazada | Alta (8.7) | 0.22% | — | DockerAIDocker MCP GatewayAI | 15/9/2026 | 30/9/2026 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in… | |
| Pendiente de análisis | Crítica (9.4) | 0.20% | — | Apple MacosAIDocker DesktopAI | 15/9/2026 | 16/9/2026 | On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host… | |
| Aplazada | Media (6.5) | 0.40% | — | Doco-cdAIDocker ComposeAIDocker SwarmAI | 11/9/2026 | 30/9/2026 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that same artifact. When… | |
| Aplazada | Alta (8.3) | 0.31% | — | Docker Socket ProxyAI | 22/8/2026 | 24/9/2026 | docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download… | |
| Pendiente de análisis | Media (5.7) | 0.14% | — | Docker SandboxesAI | 12/8/2026 | 18/8/2026 | Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox… | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI | 11/8/2026 | 9/9/2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home… | |
| Aplazada | Alta (8.7) | 3.3% | — | Openwrt Luci-app-dockermanAIOpenwrtAI | 3/8/2026 | 9/9/2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the… | |
| Pendiente de análisis | Crítica (9.1) | 0.43% | — | SupabaseAIPostgresqlAIDockerAI | 31/7/2026 | 8/9/2026 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | |
| Aplazada | Alta (7.5) | 0.45% | — | Wwbn AvideoAIApacheAIDockerAI | 16/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database… | |
| Aplazada | Baja (3.3) | 0.31% | — | Docker ComposeAIRedisAIKeydbAIDragonflyAI+4 | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the… | |
| Aplazada | Media (5.3) | 0.40% | — | Vxcontrol PentagiAIDockerAI | 6/7/2026 | 6/7/2026 | A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Crítica (9.8) | 2.8% | — | Gitea Docker ImageAI | 3/7/2026 | 7/7/2026 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | |
| Pendiente de análisis | Media (5.7) | 0.14% | — | DockerAI | 18/6/2026 | 13/8/2026 | Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as… | |
| Pendiente de análisis | Media (5.7) | 0.10% | — | Docker SandboxesAI | 18/6/2026 | 13/8/2026 | Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy. A workload inside a sandbox, which the threat model… | |
| Aplazada | Baja (3.1) | 0.17% | — | Docker RegistryAIBlacklanternsecurity BbotAI | 17/6/2026 | 22/6/2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary… | |
| Analizada | Alta (7.2) | 0.10% | — | Docker EngineMobyproject MobyMobyproject Moby/v2 | 12/6/2026 | 17/6/2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path,… | |
| Analizada | Media (6.1) | 0.10% | — | Docker EngineMobyproject MobyMobyproject Moby/v2 | 12/6/2026 | 17/6/2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on… | |
| Aplazada | Crítica (9.5) | 0.43% | — | Duck SiteAIDockerAIDokployAI | 11/6/2026 | 17/6/2026 | In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull requests, while the deploy workflow runs with package-write permissions and deployment secrets. If an attacker can make a pull request build satisfy the deploy… | |
| Pendiente de análisis | Alta (7.2) | 0.17% | — | MobyAIDocker EngineAI | 5/6/2026 | 9/9/2026 | Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the… | |
| Aplazada | Crítica (9.8) | 3.0% | — | Openlabs Docker-wkhtmltopdf-aasAI | 3/6/2026 | 22/7/2026 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request. | |
| Pendiente de análisis | Alta (8.2) | 0.15% | — | Docker DesktopAI | 2/6/2026 | 22/7/2026 | Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0. | |
| Analizada | Alta (8.8) | 0.18% | — | Docker Desktop | 22/5/2026 | 23/7/2026 | The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses… |