Docker Inc.

First CVE: Mar 13, 2023Active for: 3 years
39
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.8
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Docker Inc. as a CNA, 74.4% affect products that Docker Inc. develops as a vendor.

74.4%
25.6%
Self-reported: 29Third-party: 10

Of all the CVEs published that affect products developed by Docker Inc., 23.8% are self-published by Docker Inc. as a CNA.

23.8%
76.2%
Self-published: 29Published by other CNAs: 93

Trends Over Time

The number and severity of CVEs published by Docker Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 13, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Docker Inc. as a CNA, regardless of affected vendor or product.

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 b
Aug 20, 20259.349NOYES
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denie
May 22, 20268.837NONO
Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry
Jun 2, 20268.236NONO
The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes
May 22, 20268.636NONO
The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the
May 22, 20268.635NONO
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a
Jul 21, 20267.332NONO
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permiss
Jul 21, 20266.932NONO
Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this dire
Mar 4, 20268.031NONO
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
Sep 12, 20249.831NONO
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
Sep 12, 20249.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA39 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local28 (71.8%)
Network11 (28.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (89.7%)
High4 (10.3%)
Unknown0 (0.0%)
User Interaction
None26 (66.7%)
Unknown0 (0.0%)
Required7 (17.9%)
Privileges Required
Low24 (61.5%)
High1 (2.6%)
None14 (35.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 91st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Docker Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Docker Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs