CVE-2026-92543: CWE-295: Improper Certificate Validation in Docker Docker Engine
Description
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
CVSS v4.0
Score 7.6high
Affected software
Docker
Docker Engine
Moby
Moby
pkg:github/github.com/moby/moby/v2Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Docker Engine classifies registry hostnames as insecure based on an any-match DNS check that includes loopback CIDRs (127.0.0.0/8 and ::1/128) by default. The function isCIDRMatch resolves all IP addresses for a hostname and returns true if any address matches these insecure CIDRs. However, because the transport layer re-dials the hostname rather than the specific CIDR-matching address, an attacker can supply a DNS response containing both a loopback IP and a non-loopback attacker IP. This causes Docker Engine to disable certificate verification and fall back to HTTP, exposing the registry connection to potential interception or manipulation.
Potential Impact
This vulnerability allows an attacker to bypass TLS certificate verification for Docker registry connections, potentially enabling man-in-the-middle attacks or interception of sensitive data transmitted during image pulls or pushes. The fallback to HTTP further weakens the security of the connection, increasing the risk of data exposure or tampering.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should be cautious when configuring insecure registries and monitor Docker advisories for updates addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Docker
- Date Reserved
- 2026-09-16T13:00:33.499Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac67f132cdf04f6566891e5
Added to database: 10/07/2026, 17:19:15 UTC
Last enriched: 10/07/2026, 17:33:45 UTC
Last updated: 10/07/2026, 20:48:59 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.