Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.9)0.29%—Docker BuildxAI5/10/20266/10/2026
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side pathname, or consume a local OCI image layout outside the project after entitlement validation…
Pendiente de análisisCrítica (9.4)0.42%—Psyb0t Docker MailboxAI29/9/202629/9/2026
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or…
Pendiente de análisisAlta (8)0.52%—Noelware Docker-manifest-actionAIQuay Builder-qemuAI16/9/202618/9/2026
A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inject arbitrary code, leading to the exfiltration of sensitive registry credentials…
Pendiente de análisisAlta (8.7)0.14%—Docker SandboxesAI15/9/202616/9/2026
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary…
AplazadaAlta (8.7)0.22%—DockerAIDocker MCP GatewayAI15/9/202630/9/2026
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and catalog snapshot imports in…
Pendiente de análisisCrítica (9.4)0.20%💥 PoCApple MacosAIDocker DesktopAI15/9/202616/9/2026
On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host…
AplazadaMedia (6.5)0.40%—Doco-cdAIDocker ComposeAIDocker SwarmAI11/9/202630/9/2026
Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy used to verify that same artifact. When…
AplazadaAlta (8.3)0.31%💥 PoCDocker Socket ProxyAI22/8/202624/9/2026
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download…
Pendiente de análisisMedia (5.7)0.14%—Docker SandboxesAI12/8/202618/8/2026
Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path, so unprivileged code inside the sandbox…
Pendiente de análisisAlta (7.7)0.63%—Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home…
AplazadaAlta (8.7)3.3%—Openwrt Luci-app-dockermanAIOpenwrtAI3/8/20269/9/2026
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the…
AplazadaBaja (3.3)0.31%—ClickhouseAICoollabs CoolifyAIDocker ComposeAIDragonflyAI+17/7/20267/7/2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the…
AplazadaCrítica (9.8)2.8%💥 ExploitGitea Docker ImageAI3/7/20267/7/2026
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
Pendiente de análisisMedia (5.7)0.14%—DockerAI18/6/202613/8/2026
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as…
Pendiente de análisisMedia (5.7)0.10%—Docker SandboxesAI18/6/202613/8/2026
Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network embedded DNS server forwards any queried name to the host resolver whenever the network is internet-connected, without consulting the policy. A workload inside a sandbox, which the threat model…
AplazadaBaja (3.1)0.17%—Docker RegistryAIBlacklanternsecurity BbotAI17/6/202622/6/2026
The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle position between bbot and a Docker registry could modify this header to redirect the authentication request to an arbitrary…
AnalizadaAlta (7.2)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path,…
AnalizadaMedia (6.1)0.10%—Docker EngineMobyproject MobyMobyproject Moby/v212/6/202617/6/2026
Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on…
Pendiente de análisisAlta (7.2)0.17%💥 PoCMobyAIDocker EngineAI5/6/20269/9/2026
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the…
AplazadaCrítica (9.8)3.0%—Openlabs Docker-wkhtmltopdf-aasAI3/6/202622/7/2026
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
Pendiente de análisisAlta (8.2)0.15%—Docker DesktopAI2/6/202622/7/2026
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry invalidation event. This issue has been fixed in Docker Desktop 4.76.0.
AnalizadaAlta (8.8)0.18%💥 PoCDocker Desktop22/5/202623/7/2026
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the model_file configuration field in config.json. When a model's config.json specifies a model_file pointing to a Python file, MLX-LM uses…
AnalizadaAlta (8.8)0.18%💥 PoCDocker Desktop22/5/202623/7/2026
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to import and execute arbitrary Python files included in any model pulled from an OCI…
AnalizadaAlta (8.8)0.20%—Docker Desktop22/5/202623/7/2026
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly allowed via the admin-settings configuration. However, the --use-api-socket flag adds the Docker socket mount via the…
AplazadaAlta (7.4)0.41%—Mailcow-dockerizedAI20/5/202624/7/2026
mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without adequate output…
Orbitaley — Vulnerabilidades