{"schema_version":1,"title":"github.com/docker/docker (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 37 vulnerabilities in github.com/docker/docker (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-42306, was published on 12 June 2026.","url":"https://junglewise.ai/threats/technologies/github-com-docker-docker","json_url":"https://junglewise.ai/threats/technologies/github-com-docker-docker.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-docker-docker","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":37,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2026-42306","cvss":7.2,"epss":0.001,"slug":"cve-2026-42306-moby-docker-engine-race-condition-in-docker-cp-mount-setup","title":"Moby Docker Engine race condition in docker cp mount setup","severity":"high","exploited":false,"published_at":"2026-06-12T19:16:27.49+00:00","url":"https://junglewise.ai/threats/cve-2026-42306-moby-docker-engine-race-condition-in-docker-cp-mount-setup"},{"cve":"CVE-2026-41568","cvss":6.1,"epss":0.001,"slug":"cve-2026-41568-moby-docker-engine-symlink-race-condition-in-docker-cp","title":"Moby Docker Engine symlink race condition in docker cp","severity":"medium","exploited":false,"published_at":"2026-06-12T19:16:26.907+00:00","url":"https://junglewise.ai/threats/cve-2026-41568-moby-docker-engine-symlink-race-condition-in-docker-cp"},{"cve":"CVE-2026-41567","cvss":7.2,"epss":0.0017,"slug":"cve-2026-41567-moby-and-docker-engine-code-execution-via-trojanized","title":"Moby and Docker Engine code execution via trojanized decompression binaries","severity":"high","exploited":false,"published_at":"2026-06-05T02:17:13.817+00:00","url":"https://junglewise.ai/threats/cve-2026-41567-moby-and-docker-engine-code-execution-via-trojanized"},{"cve":"CVE-2026-34040","cvss":8.8,"epss":0.0016,"slug":"cve-2026-34040-moby-authz-plugin-authorization-bypass-via-oversized-request-body","title":"Moby AuthZ plugin authorization bypass via oversized request body","severity":"high","exploited":false,"published_at":"2026-03-31T03:15:57.883+00:00","url":"https://junglewise.ai/threats/cve-2026-34040-moby-authz-plugin-authorization-bypass-via-oversized-request-body"},{"cve":"CVE-2026-33997","cvss":6.8,"epss":0.0051,"slug":"cve-2026-33997-moby-privilege-validation-bypass-in-docker-plugin-install","title":"Moby privilege validation bypass in docker plugin install","severity":"medium","exploited":false,"published_at":"2026-03-31T03:15:57.523+00:00","url":"https://junglewise.ai/threats/cve-2026-33997-moby-privilege-validation-bypass-in-docker-plugin-install"},{"cve":"CVE-2025-54410","cvss":3.1,"epss":0.0016,"slug":"cve-2025-54410-moby-firewalld-reload-removes-bridge-network-isolation","title":"GO-2025-3829 - Moby firewalld reload removes bridge network isolation in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-54410-moby-firewalld-reload-removes-bridge-network-isolation"},{"cve":"CVE-2025-54388","cvss":3.1,"epss":0.0022,"slug":"cve-2025-54388-moby-firewalld-reload-makes-published-container-ports-accessible","title":"GO-2025-3830 - Moby firewalld reload makes published container ports accessible from remote hosts in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2025-08-11T17:24:51+00:00","url":"https://junglewise.ai/threats/cve-2025-54388-moby-firewalld-reload-makes-published-container-ports-accessible"},{"slug":"go-2022-1107-container-build-can-leak-any-path-on-the-host-into-the-a66365ae","title":"GO-2022-1107 - Container build can leak any path on the host into the container in github.com/docker/docker","severity":"info","exploited":false,"published_at":"2024-08-21T16:03:26+00:00","url":"https://junglewise.ai/threats/go-2022-1107-container-build-can-leak-any-path-on-the-host-into-the-a66365ae"},{"cve":"CVE-2022-36109","cvss":3.1,"epss":0.0104,"slug":"cve-2022-36109-docker-supplementary-group-permissions-not-set-up-properly","title":"GO-2022-0985 - Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions in github.com/docker/doc","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:24+00:00","url":"https://junglewise.ai/threats/cve-2022-36109-docker-supplementary-group-permissions-not-set-up-properly"},{"cve":"CVE-2014-3499","cvss":3.1,"epss":0.0039,"slug":"cve-2014-3499-privilege-escalation-in-docker","title":"GO-2022-0752 - Privilege Escalation in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2014-3499-privilege-escalation-in-docker"},{"cve":"CVE-2014-9358","cvss":3.1,"epss":0.0253,"slug":"cve-2014-9358-directory-traversal-in-docker","title":"GO-2022-0705 - Directory Traversal in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2014-9358-directory-traversal-in-docker"},{"cve":"CVE-2014-9356","cvss":3.1,"epss":0.0492,"slug":"cve-2014-9356-path-traversal-in-docker","title":"GO-2022-0751 - Path Traversal in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2014-9356-path-traversal-in-docker"},{"cve":"CVE-2015-3627","epss":0.0061,"slug":"cve-2015-3627-symlink-attack-in-libcontainer-and-docker-engine","title":"GO-2022-0649 - Symlink Attack in Libcontainer and Docker Engine in github.com/docker/docker","severity":"info","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2015-3627-symlink-attack-in-libcontainer-and-docker-engine"},{"cve":"CVE-2015-3629","cvss":3.1,"epss":0.006,"slug":"cve-2015-3629-arbitrary-file-write-in-libcontainer","title":"GO-2022-0647 - Arbitrary File Write in Libcontainer in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2015-3629-arbitrary-file-write-in-libcontainer"},{"cve":"CVE-2015-3631","cvss":3.1,"epss":0.0057,"slug":"cve-2015-3631-arbitrary-file-override-in-docker-engine","title":"GO-2022-0708 - Arbitrary File Override in Docker Engine in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2015-3631-arbitrary-file-override-in-docker-engine"},{"cve":"CVE-2014-9357","cvss":3.1,"epss":0.062,"slug":"cve-2014-9357-arbitrary-code-execution","title":"GO-2022-0640 - Arbitrary Code Execution in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-9357-arbitrary-code-execution"},{"cve":"CVE-2014-5277","cvss":3.1,"epss":0.0187,"slug":"cve-2014-5277-pysec-2014-80-docker-before-1-3-1-and-docker-py-before-0-5-3-fall","title":"GO-2022-0636 - Man-in-the-Middle (MitM) in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-5277-pysec-2014-80-docker-before-1-3-1-and-docker-py-before-0-5-3-fall"},{"cve":"CVE-2014-6408","epss":0.0314,"slug":"cve-2014-6408-access-restriction-bypass-in-docker","title":"GO-2022-0625 - Access Restriction Bypass in Docker in github.com/docker/docker","severity":"info","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-6408-access-restriction-bypass-in-docker"},{"cve":"CVE-2014-6407","cvss":3.1,"epss":0.0491,"slug":"cve-2014-6407-arbitrary-code-execution-in-docker","title":"GO-2022-0630 - Arbitrary Code Execution in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-6407-arbitrary-code-execution-in-docker"},{"cve":"CVE-2015-3630","cvss":3.1,"epss":0.0055,"slug":"cve-2015-3630-information-exposure-in-docker-engine","title":"GO-2022-0638 - Information Exposure in Docker Engine in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2015-3630-information-exposure-in-docker-engine"},{"cve":"CVE-2022-24769","cvss":3.1,"epss":0.0049,"slug":"cve-2022-24769-moby-docker-engine-started-with-non-empty-inheritable-linux","title":"GO-2022-0390 - Moby (Docker Engine) started with non-empty inheritable Linux process capabilities in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:31+00:00","url":"https://junglewise.ai/threats/cve-2022-24769-moby-docker-engine-started-with-non-empty-inheritable-linux"},{"cve":"CVE-2023-28842","cvss":3.1,"epss":0.0144,"slug":"cve-2023-28842-docker-swarm-encrypted-overlay-network-with-a-single-endpoint-is","title":"GO-2023-1701 - Docker Swarm encrypted overlay network with a single endpoint is unauthenticated in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-20T20:29:19+00:00","url":"https://junglewise.ai/threats/cve-2023-28842-docker-swarm-encrypted-overlay-network-with-a-single-endpoint-is"},{"cve":"CVE-2023-28841","cvss":3.1,"epss":0.0069,"slug":"cve-2023-28841-docker-swarm-encrypted-overlay-network-traffic-may-be-unencrypted","title":"GO-2023-1700 - Docker Swarm encrypted overlay network traffic may be unencrypted in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-20T20:29:19+00:00","url":"https://junglewise.ai/threats/cve-2023-28841-docker-swarm-encrypted-overlay-network-traffic-may-be-unencrypted"},{"cve":"CVE-2023-28840","cvss":3.1,"epss":0.0256,"slug":"cve-2023-28840-docker-swarm-encrypted-overlay-network-may-be-unauthenticated","title":"GO-2023-1699 - Docker Swarm encrypted overlay network may be unauthenticated in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-20T20:29:17+00:00","url":"https://junglewise.ai/threats/cve-2023-28840-docker-swarm-encrypted-overlay-network-may-be-unauthenticated"},{"cve":"CVE-2024-41110","cvss":3.1,"epss":0.165,"slug":"cve-2024-41110-authz-zero-length-regression","title":"GO-2024-3005 - Moby authz zero length regression in github.com/moby/moby","severity":"low","exploited":false,"published_at":"2024-07-29T18:08:44+00:00","url":"https://junglewise.ai/threats/cve-2024-41110-authz-zero-length-regression"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/docker/docker (Go)","slug":"github-com-docker-docker","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://www.docker.com/","repo_url":"https://github.com/docker/docker","description":"The core source code repository for the Docker container engine and platform.","url":"https://junglewise.ai/threats/technologies/github-com-docker-docker"},"most_severe":[{"cve":"CVE-2026-34040","cvss":8.8,"epss":0.0016,"slug":"cve-2026-34040-moby-authz-plugin-authorization-bypass-via-oversized-request-body","title":"Moby AuthZ plugin authorization bypass via oversized request body","severity":"high","exploited":false,"published_at":"2026-03-31T03:15:57.883+00:00","url":"https://junglewise.ai/threats/cve-2026-34040-moby-authz-plugin-authorization-bypass-via-oversized-request-body"},{"cve":"CVE-2026-41567","cvss":7.2,"epss":0.0017,"slug":"cve-2026-41567-moby-and-docker-engine-code-execution-via-trojanized","title":"Moby and Docker Engine code execution via trojanized decompression binaries","severity":"high","exploited":false,"published_at":"2026-06-05T02:17:13.817+00:00","url":"https://junglewise.ai/threats/cve-2026-41567-moby-and-docker-engine-code-execution-via-trojanized"},{"cve":"CVE-2026-42306","cvss":7.2,"epss":0.001,"slug":"cve-2026-42306-moby-docker-engine-race-condition-in-docker-cp-mount-setup","title":"Moby Docker Engine race condition in docker cp mount setup","severity":"high","exploited":false,"published_at":"2026-06-12T19:16:27.49+00:00","url":"https://junglewise.ai/threats/cve-2026-42306-moby-docker-engine-race-condition-in-docker-cp-mount-setup"},{"cve":"CVE-2026-33997","cvss":6.8,"epss":0.0051,"slug":"cve-2026-33997-moby-privilege-validation-bypass-in-docker-plugin-install","title":"Moby privilege validation bypass in docker plugin install","severity":"medium","exploited":false,"published_at":"2026-03-31T03:15:57.523+00:00","url":"https://junglewise.ai/threats/cve-2026-33997-moby-privilege-validation-bypass-in-docker-plugin-install"},{"cve":"CVE-2026-41568","cvss":6.1,"epss":0.001,"slug":"cve-2026-41568-moby-docker-engine-symlink-race-condition-in-docker-cp","title":"Moby Docker Engine symlink race condition in docker cp","severity":"medium","exploited":false,"published_at":"2026-06-12T19:16:26.907+00:00","url":"https://junglewise.ai/threats/cve-2026-41568-moby-docker-engine-symlink-race-condition-in-docker-cp"},{"cve":"CVE-2019-14271","cvss":3.1,"epss":0.1883,"slug":"cve-2019-14271-moby-docker-cp-broken-with-debian-containers","title":"GO-2024-2521 - Moby Docker cp broken with debian containers in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-06-28T15:28:53+00:00","url":"https://junglewise.ai/threats/cve-2019-14271-moby-docker-cp-broken-with-debian-containers"},{"cve":"CVE-2024-41110","cvss":3.1,"epss":0.165,"slug":"cve-2024-41110-authz-zero-length-regression","title":"GO-2024-3005 - Moby authz zero length regression in github.com/moby/moby","severity":"low","exploited":false,"published_at":"2024-07-29T18:08:44+00:00","url":"https://junglewise.ai/threats/cve-2024-41110-authz-zero-length-regression"},{"cve":"CVE-2014-9357","cvss":3.1,"epss":0.062,"slug":"cve-2014-9357-arbitrary-code-execution","title":"GO-2022-0640 - Arbitrary Code Execution in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-9357-arbitrary-code-execution"},{"cve":"CVE-2014-9356","cvss":3.1,"epss":0.0492,"slug":"cve-2014-9356-path-traversal-in-docker","title":"GO-2022-0751 - Path Traversal in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2014-9356-path-traversal-in-docker"},{"cve":"CVE-2014-6407","cvss":3.1,"epss":0.0491,"slug":"cve-2014-6407-arbitrary-code-execution-in-docker","title":"GO-2022-0630 - Arbitrary Code Execution in Docker in github.com/docker/docker","severity":"low","exploited":false,"published_at":"2024-08-21T15:11:40+00:00","url":"https://junglewise.ai/threats/cve-2014-6407-arbitrary-code-execution-in-docker"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}