Docker Inc.
First CVE: Mar 13, 2023Active for: 3 years
39
CVEs Published
More CVEs Published than 52% of tracked CNAs
9.8
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Docker Inc. as a CNA, 74.4% affect products that Docker Inc. develops as a vendor.
74.4%
25.6%
Self-reported: 29Third-party: 10
Of all the CVEs published that affect products developed by Docker Inc., 23.8% are self-published by Docker Inc. as a CNA.
23.8%
76.2%
Self-published: 29Published by other CNAs: 93
Trends Over Time
The number and severity of CVEs published by Docker Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 13, 2023
3 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Docker Inc. as a CNA, regardless of affected vendor or product.
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9074CRITICAL A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 b | Aug 20, 2025 | 9.3 | 49 | NO | YES |
CVE-2026-6406HIGH The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denie | May 22, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-8936HIGH Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry | Jun 2, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-5817HIGH The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes | May 22, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-5843HIGH The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the | May 22, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-15793HIGH BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a | Jul 21, 2026 | 7.3 | 32 | NO | NO |
CVE-2026-15789MEDIUM A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permiss | Jul 21, 2026 | 6.9 | 32 | NO | NO |
CVE-2025-15558HIGH Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this dire | Mar 4, 2026 | 8.0 | 31 | NO | NO |
CVE-2024-8696CRITICAL A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. | Sep 12, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-8695CRITICAL A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. | Sep 12, 2024 | 9.8 | 31 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA39 CVEs
36%
49%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (71.8%)
Network11 (28.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (89.7%)
High4 (10.3%)
Unknown0 (0.0%)
User Interaction
None26 (66.7%)
Unknown0 (0.0%)
Required7 (17.9%)
Privileges Required
Low24 (61.5%)
High1 (2.6%)
None14 (35.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.6% of CVEs· 91st percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Docker Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Docker Inc. as a CNA — matched by CVE ID, not by organization name.