Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-5277

19
FAUCET Score

CVE-2014-5277 describes a vulnerability in Docker before version 1.3.1 and docker-py before 0.5.3, where the client would downgrade to HTTP if an HTTPS connection to the registry failed. This allowed man-in-the-middle attackers to conduct downgrade attacks, intercepting authentication and image data by blocking HTTPS traffic. With a CVSS score of 5.0, this vulnerability has a network attack vector and low attack complexity, potentially leading to information disclosure. While not listed on the KEV catalog, there is some community discussion and media coverage, indicating awareness, but no known active exploits or public exploit code like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.3.0CPE matchmatch criteria
cpe:2.3:a:docker:docker:*:*:*:*:*:*:*:*
<= 0.5.3CPE matchmatch criteria
cpe:2.3:a:docker:docker-py:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.87%
Probability of exploitation in next 30 days
EPSS Percentile
77.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0187 is in the 65th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 1.3.1
microsoftpatch availablevia msrc
Product: cm1 moby-buildx 0.4.1+azure-3 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: 16833-16820Fixed in: -
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 0.4.1+azure-3
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 0.4.1+azure-3
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: docker

Vendor Advisories (4)

goGHSA-8w94-cf6g-c8mgmedium

Man-in-the-Middle (MitM)

Feb 15, 2022
microsoft2021-Jul/CVE-2014-5277

CVE-2014-5277

Jul 13, 2021
microsoft2014-Nov/CVE-2014-5277Moderate

Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position between the client and the registry to block HTTPS traffic.

Nov 2, 2014
redhatCVE-2014-5277Moderate

docker: fallback to HTTP when HTTPS connections to the registry fail

Oct 30, 2014

References

lists.opensuse.org / opensuse-updates/2014-11/msg00048.html
groups.google.com / forum