Image

Docker CLI — Known Vulnerabilities

53 vulnerabilities mapped, 1 on the CISA actively-exploited list. Grouped by the release each fix landed in — newest tracked release v2025-9074.
Still affects the latest release (v2025-9074) 27
CVE-2022-34883 Affects current release CVSS 8.8 · High NVD ↗ Sep 6, 2022
OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows; 02.05.00 versions…
CVE-2021-29742 Affects current release CVSS 8.0 · High NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a user to impersonate another user on the system. IBM X-Force ID: 201483.
CVE-2014-0047 Affects current release CVSS 7.8 · High NVD ↗ Oct 6, 2017
Docker before 1.5 allows local users to have unspecified impact via vectors involving unsafe /tmp usage.
CVE-2016-3697 Affects current release CVSS 7.8 · High NVD ↗ Jun 1, 2016
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
CVE-2021-20497 Affects current release CVSS 7.5 · High NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197969
CVE-2019-16884 Affects current release CVSS 7.5 · High NVD ↗ Sep 25, 2019
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
CVE-2014-6407 Affects current release CVSS 7.5 · High NVD ↗ Dec 12, 2014
Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.
CVE-2021-20533 Affects current release CVSS 7.2 · High NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 198813
CVE-2015-3630 Affects current release CVSS 7.2 · High NVD ↗ May 18, 2015
Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows local users to modify the host, obtain sensitive information, and perform protocol downgrade attacks via a crafted image.
CVE-2015-3627 Affects current release CVSS 7.2 · High NVD ↗ May 18, 2015
Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image.
CVE-2021-29699 Affects current release CVSS 6.8 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote priviled user to upload arbitrary files with a dangerous file type that could be excuted by an user. IBM X-Force ID: 200600.
CVE-2022-34882 Affects current release CVSS 6.5 · Medium NVD ↗ Sep 6, 2022
Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows;…
CVE-2021-20537 Affects current release CVSS 6.5 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID:198918
CVE-2017-14992 Affects current release CVSS 6.5 · Medium NVD ↗ Nov 1, 2017
Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload,…
CVE-2014-9358 Affects current release CVSS 6.4 · Medium NVD ↗ Dec 16, 2014
Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."
CVE-2021-20498 Affects current release CVSS 5.3 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 reveals version information in HTTP requests that could be used in further attacks against the system. IBM X-Force ID: 197972.
CVE-2018-10892 Affects current release CVSS 5.3 · Medium NVD ↗ Jul 6, 2018
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
CVE-2014-5277 Affects current release CVSS 5.0 · Medium NVD ↗ Nov 17, 2014
Docker before 1.3.1 and docker-py before 0.5.3 fall back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and obtain authentication and image data by leveraging a network position…
CVE-2021-20496 Affects current release CVSS 4.9 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow an authenticated user to bypass input due to improper input validation. IBM X-Force ID: 197966.
CVE-2021-20511 Affects current release CVSS 4.9 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM…
CVE-2021-20524 Affects current release CVSS 4.8 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.…
CVE-2021-20500 Affects current release CVSS 4.4 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could reveal highly sensitive information to a local privileged user. IBM X-Force ID: 197980.
CVE-2021-20510 Affects current release CVSS 4.4 · Medium NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 198299
CVE-2015-3631 Affects current release CVSS 3.6 · Low NVD ↗ May 18, 2015
Docker Engine before 1.6.1 allows local users to set arbitrary Linux Security Modules (LSM) and docker_t policies via an image that allows volumes to override files in /proc.
CVE-2021-20534 Affects current release CVSS 3.5 · Low NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability…
CVE-2021-20499 Affects current release CVSS 2.7 · Low NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…
CVE-2021-20523 Affects current release CVSS 2.7 · Low NVD ↗ Jul 15, 2021
IBM Security Verify Access Docker 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM…
Fixed in v20.x 2
CVE-2021-21284 Fixed in 20.10.3 CVSS 6.8 · Medium NVD ↗ Feb 2, 2021
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root user in the remapped namespace has…
CVE-2021-21285 Fixed in 20.10.3 CVSS 6.5 · Medium NVD ↗ Feb 2, 2021
In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker image manifest crashes the dockerd daemon. Versions 20.10.3 and 19.03.15 contain patches that prevent the daemon from crashing.
Fixed in v19.x 2
CVE-2019-14271 Fixed in 19.03.1 CVSS 9.8 · Critical NVD ↗ Jul 29, 2019
In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitch facility dynamically loads a library inside a chroot that contains the contents of the container.
CVE-2020-27534 Fixed in 19.03.9 CVSS 5.3 · Medium NVD ↗ Dec 30, 2020
util/binfmt_misc/check.go in Builder in Docker Engine before 19.03.9 calls os.OpenFile with a potentially unsafe qemu-check temporary pathname, constructed with an empty first argument in an ioutil.TempDir call.
Fixed in v18.x 5
CVE-2018-15514 Affects 1.10.0.0-0–18.05.0 CVSS 8.8 · High NVD ↗ Sep 1, 2018
HandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests over the \\.\pipe\dockerBackend named pipe without verifying the validity of the deserialized .NET objects. This would allow a malicious user in the "docker-users" group…
CVE-2019-5736 Fixed in 18.09.2 CVSS 8.6 · High NVD ↗ Feb 11, 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one…
CVE-2019-13139 Fixed in 18.09.4 CVSS 8.4 · High NVD ↗ Aug 22, 2019
In Docker before 18.09.4, an attacker who is capable of supplying or manipulating the build path for the "docker build" command would be able to gain command execution. An issue exists in the way "docker build" processes remote…
CVE-2019-13509 Fixed in 18.09.8 CVSS 7.5 · High NVD ↗ Jul 18, 2019
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometimes add secrets to the debug log. This applies to a scenario where docker…
CVE-2018-15664 Affects 17.06.0-ce–18.06.1-ce CVSS 7.5 · High NVD ↗ May 23, 2019
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access to the host filesystem with root privileges, because daemon/archive.go does not do…
Fixed in v4.x 1
CVE-2022-25365 Fixed in 4.5.1 CVSS 7.8 · High NVD ↗ Feb 19, 2022
Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.
Fixed in v2.x 2
CVE-2019-15752 Fixed in 2.1.0.1 CVSS 7.8 · High NVD ↗ CISA KEV ↗ Aug 28, 2019
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low-privilege user, and then waiting for an admin or service user to authenticate with Docker,…
CVE-2021-3162 Fixed in 2.5.0.0 CVSS 7.8 · High NVD ↗ Jan 15, 2021
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
Fixed in v1.x 14
CVE-2014-9357 Affects 1.3.2–1.3.2 CVSS 10.0 · High NVD ↗ Dec 16, 2014
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction.
CVE-2014-0048 Fixed in 1.5.0 CVSS 9.8 · Critical NVD ↗ Jan 2, 2020
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
CVE-2020-14300 Affects 1.13.1–1.13.1 CVSS 8.8 · High NVD ↗ Jul 13, 2020
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that…
CVE-2020-14298 Affects 1.13.1–1.13.1 CVSS 8.8 · High NVD ↗ Jul 13, 2020
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a…
CVE-2014-9356 Fixed in 1.3.3 CVSS 8.6 · High NVD ↗ Dec 2, 2019
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.
CVE-2014-5282 Fixed in 1.3 CVSS 8.1 · High NVD ↗ Feb 6, 2018
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
CVE-2014-8179 Fixed in 1.8.3 CVSS 7.5 · High NVD ↗ Dec 17, 2019
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to inject new attributes in a JSON object and…
CVE-2016-8867 Affects 1.12.2–1.12.2 CVSS 7.5 · High NVD ↗ Oct 28, 2016
Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.
CVE-2014-3499 Affects 1.0.0–1.0.0 CVSS 7.2 · High NVD ↗ Jul 11, 2014
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.
CVE-2016-6595 Affects 1.12.0–1.12.0 CVSS 6.5 · Medium NVD ↗ Jan 4, 2017
The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this…
CVE-2016-9962 Fixed in 1.12.6 CVSS 6.4 · Medium NVD ↗ Jan 31, 2017
RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new…
CVE-2014-8178 Fixed in 1.8.3 CVSS 5.5 · Medium NVD ↗ Dec 17, 2019
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a crafted image in pull…
CVE-2014-5278 Fixed in 1.2.0 CVSS 5.3 · Medium NVD ↗ Feb 7, 2020
A vulnerability exists in Docker before 1.2 via container names, which may collide with and override container IDs.
CVE-2014-6408 Affects 1.3.0–1.3.1 CVSS 5.0 · Medium NVD ↗ Dec 12, 2014
Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.
Source: NVD · CISA KEV · data as of Jun 8, 2026