Docker Inc. maintains a focused but strategically central portfolio of containerization and orchestration products—including Docker Engine, Docker Desktop, and associated command-line tooling—that have become foundational to modern application deployment and development workflows. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the privileged runtime position these tools occupy in infrastructure stacks. The recurring exposure centers on improper input validation, insufficient link resolution and file-access controls, and missing authentication mechanisms for critical functions, patterns consistent with the complexity of container runtimes and the security-sensitive nature of file and network isolation in containerized environments. Defenders should prioritize updates to Docker's offerings, particularly in development and production orchestration contexts where a compromise can propagate across workloads. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Docker Inc. over time
Of all the CVEs published by Docker Inc. as a CNA, 74.4% affect products that Docker Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Docker Inc., 23.8% are self-published by Docker Inc. as a CNA.
Signals from CVEs in this vendor scope (122 CVEs).
122 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2019-15752HIGH Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\ve | Aug 28, 2019 | 7.8 | 88 | YES | YES |
CVE-2025-9074CRITICAL A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 b | Aug 20, 2025 | 9.3 | 49 | NO | YES |
CVE-2019-14271CRITICAL In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that | Jul 29, 2019 | 9.8 | 41 | NO | NO |
CVE-2026-34040HIGH Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This | Mar 31, 2026 | 7.8 | 39 | NO | NO |
CVE-2026-6406HIGH The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denie | May 22, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-8936HIGH Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry | Jun 2, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-5817HIGH The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes | May 22, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-5843HIGH The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the | May 22, 2026 | 8.6 | 35 | NO | NO |
CVE-2014-9357HIGH Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the ch | Dec 16, 2014 | 10.0 | 34 | NO | NO |
Signals from CVEs in this vendor scope (122 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Docker Inc..
Media articles that mention a CVE ID that affects a product developed by Docker Inc. — matched by CVE ID, not by vendor name.