Docker Desktop
Vendor:
First CVE: Jun 5, 2020 · Active for 6 years
34
Total CVEs
More Total CVEs than 96% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Docker Desktop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2020
6 years ago
Most Recent CVE
Jun 2, 2026
52 days ago
CVE Severity & Scoring
Docker Desktop34 CVEs
26%
59%
15%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local25 (73.5%)
Network9 (26.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (88.2%)
High4 (11.8%)
Unknown0 (0.0%)
User Interaction
None27 (79.4%)
Unknown0 (0.0%)
Required5 (14.7%)
Privileges Required
Low21 (61.8%)
High0 (0.0%)
None13 (38.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9074CRITICAL A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 b | Aug 20, 2025 | 9.3 | 49 | NO | YES |
CVE-2026-6406HIGH The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denie | May 22, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-8936HIGH Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder and triggered a dentry | Jun 2, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-5817HIGH The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes | May 22, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-5843HIGH The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories via the | May 22, 2026 | 8.6 | 35 | NO | NO |
CVE-2024-8696CRITICAL A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2. | Sep 12, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-8695CRITICAL A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2. | Sep 12, 2024 | 9.8 | 31 | NO | NO |
CVE-2023-0625CRITICAL Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog.
This issue affects Docker Desktop: before 4.12.0.
| Sep 25, 2023 | 9.8 | 31 | NO | NO |
CVE-2025-9164HIGH Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for required DLLs in the user's Downloads folder before checkin | Oct 27, 2025 | 8.8 | 29 | NO | NO |
CVE-2023-0626CRITICAL Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route.
This issue affects Docker Desktop: before 4.12.0.
| Sep 25, 2023 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Docker Desktop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.3.1 | 1 | 5.5 | 0.4% | 0 | 0 |
| 4.3.0 | 1 | 5.5 | 0.4% | 0 | 0 |
| 2.3.0.3 | 1 | 7.8 | 0.7% | 0 | 0 |