Engine Docker Engine

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Docker Engine.

By the Year

In 2026 there have been 2 vulnerabilities in Docker Engine with an average score of 7.3 out of ten. Engine did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 2 7.25
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 1 6.00
2019 1 0.00

It may take a day or so for new Engine vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Docker Engine Security Vulnerabilities

Docker Engine classifies a registry hostname as insecure using an any-match DNS check
CVE-2026-92543 7.6 - High - October 07, 2026

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

Improper Certificate Validation

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent
CVE-2026-92542 6.9 - Medium - October 07, 2026

The firewall rules which mark VXLAN datagrams for encryption indiscriminately match both authentic VXLAN datagrams sent from the kernel and forged datagrams sent by user processes. Any packet sent from the host network namespace of a Linux Swarm node is encrypted with the overlay-network IPsec parameters which meets the following criteria: - UDP datagram - Destination port is the Swarm data-path port - Datagram starts with a VXLAN header for the VNI of an encrypted overlay network which any running container on the node is connected to

Authentication Bypass by Spoofing

An issue was discovered in Docker Engine before 19.03.11
CVE-2020-13401 6 - Medium - June 02, 2020

An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.

Improper Input Validation

Docker Engine before 18.09
CVE-2018-20699 - January 12, 2019

Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Docker Engine or by Docker? Click the Watch button to subscribe.

Docker
Vendor

Docker Engine
Product

subscribe