cbcvebase.
CVE-2026-64777
published 2026-08-20

CVE-2026-64777: A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when…

PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.23%
13.9th percentile
A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.

Affected

1 ranges
VendorProductVersion rangeFixed in
applecontainer< 1.2.01.2.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.