Skip to main content

CVE-2026-92543: CWE-295: Improper Certificate Validation in Docker Docker Engine

0
High
VulnerabilityCVE-2026-92543cvecve-2026-92543cwe-295cwe-319
Published: 10/07/2026 (10/07/2026, 16:44:21 UTC)
Source: CVE Database V5
Vendor/Project: Docker
Product: Docker Engine

Description

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

CVSS v4.0

Score 7.6high

Attack Vector
Network
Attack Complexity
High
Attack Requirements
Present
Privileges Required
None
User Interaction
Passive
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected software

Docker

Docker Engine

Affected versions
>=0 <29.8.2

Moby

Moby

Affected versions
>=0 <2.0.0-beta.25
GitHub Actionsmore threats →cve
github.com/moby/moby/v2
pkg:github/github.com/moby/moby/v2
Affected versions
>=0 <2.0.0-beta.25

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 17:33:45 UTC

Technical Analysis

Docker Engine classifies registry hostnames as insecure based on an any-match DNS check that includes loopback CIDRs (127.0.0.0/8 and ::1/128) by default. The function isCIDRMatch resolves all IP addresses for a hostname and returns true if any address matches these insecure CIDRs. However, because the transport layer re-dials the hostname rather than the specific CIDR-matching address, an attacker can supply a DNS response containing both a loopback IP and a non-loopback attacker IP. This causes Docker Engine to disable certificate verification and fall back to HTTP, exposing the registry connection to potential interception or manipulation.

Potential Impact

This vulnerability allows an attacker to bypass TLS certificate verification for Docker registry connections, potentially enabling man-in-the-middle attacks or interception of sensitive data transmitted during image pulls or pushes. The fallback to HTTP further weakens the security of the connection, increasing the risk of data exposure or tampering.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should be cautious when configuring insecure registries and monitor Docker advisories for updates addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Docker
Date Reserved
2026-09-16T13:00:33.499Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac67f132cdf04f6566891e5

Added to database: 10/07/2026, 17:19:15 UTC

Last enriched: 10/07/2026, 17:33:45 UTC

Last updated: 10/07/2026, 20:48:59 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses