cbcvebase.

Docker Engine vulnerabilities

6 known vulnerabilities affecting docker/engine.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2026-34040P3HIGHCVSS 7.8fixed in 29.3.12026-03-31
CVE-2026-34040 [HIGH] CWE-288 CVE-2026-34040: Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has be Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
nvd
CVE-2026-33997P3HIGHCVSS 8.1fixed in 29.3.12026-03-31
CVE-2026-33997 [HIGH] CWE-193 CVE-2026-33997: Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has be Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorrectly accept a privilege set that differs from the one approved by the use
nvd
CVE-2026-42306P3HIGHCVSS 7.2fixed in 29.5.12026-06-12
CVE-2026-42306 [HIGH] CWE-61 CVE-2026-42306: Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing
nvd
CVE-2020-13401P4MEDIUMCVSS 6.0fixed in 19.03.112020-06-02
CVE-2020-13401 [MEDIUM] CWE-20 CVE-2020-13401: An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_N An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
nvd
CVE-2026-41568P4MEDIUMCVSS 6.1fixed in 29.5.12026-06-12
CVE-2026-41568 [MEDIUM] CWE-81 CVE-2026-41568: Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has
nvd
CVE-2018-20699P4MEDIUMCVSS 4.9fixed in 18.092019-01-12
CVE-2018-20699 [MEDIUM] CWE-400 CVE-2018-20699: Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
nvd
Docker Engine vulnerabilities | cvebase