VendorsDockerdocker_desktopall versions
Vulnerabilities

Docker Desktop

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2023-0625
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2023-0626
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2023-5165
Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell
Published 2023-09-25 · Modified
8.8EPSS 0.002
CVE-2026-5843
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-5817
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-6406
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2021-44719
Docker Desktop 4.3.0 has Incorrect Access Control.
Published 2022-05-25 · Modified
8.4EPSS 0.003
CVE-2023-5166
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL
Published 2023-09-25 · Modified
8.0EPSS 0.007
CVE-2020-11492
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.
Published 2020-06-05 · Modified
7.8EPSS 0.009
CVE-2020-15360
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
Published 2020-06-27 · Modified
7.8EPSS 0.007
CVE-2023-0633
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPE
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2023-0628
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL
Published 2023-03-13 · Modified
7.8EPSS 0.003
CVE-2023-0627
Docker Desktop 4.11.x allows --no-windows-containers flag bypass
Published 2023-09-25 · Modified
7.8EPSS 0.002
CVE-2025-13743
Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs
Published 2025-12-09 · Analyzed
7.5EPSS 0.002
CVE-2022-26659
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
Published 2022-03-25 · Modified
7.1EPSS 0.004
CVE-2023-0629
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged containers
Published 2023-03-13 · Modified
7.1EPSS 0.002
CVE-2021-45449
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files.
Published 2022-01-12 · Modified
5.5EPSS 0.004
CVE-2022-23774
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
Published 2022-02-01 · Modified
5.3EPSS 0.009