VendorsDockerdocker_desktopany version
Vulnerabilities

Docker Desktop any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-0625
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2023-0626
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route
Published 2023-09-25 · Modified
9.8EPSS 0.007
CVE-2023-5165
Docker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shell
Published 2023-09-25 · Modified
8.8EPSS 0.002
CVE-2026-5817
Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-5843
Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2026-6406
Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag
Published 2026-05-22 · Analyzed
8.8EPSS 0.002
CVE-2021-44719
Docker Desktop 4.3.0 has Incorrect Access Control.
Published 2022-05-25 · Modified
8.4EPSS 0.003
CVE-2023-5166
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL
Published 2023-09-25 · Modified
8.0EPSS 0.007
CVE-2020-11492
An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and then impersonate their privileges.
Published 2020-06-05 · Modified
7.8EPSS 0.009
CVE-2023-0633
In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in LPE
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2023-0628
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL
Published 2023-03-13 · Modified
7.8EPSS 0.003
CVE-2023-0627
Docker Desktop 4.11.x allows --no-windows-containers flag bypass
Published 2023-09-25 · Modified
7.8EPSS 0.002
CVE-2025-13743
Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs
Published 2025-12-09 · Analyzed
7.5EPSS 0.002
CVE-2022-26659
Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, when run elevated, will write its log files to a location not writable by non-administrator users.
Published 2022-03-25 · Modified
7.1EPSS 0.004
CVE-2023-0629
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged containers
Published 2023-03-13 · Modified
7.1EPSS 0.002
CVE-2022-23774
Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files.
Published 2022-02-01 · Modified
5.3EPSS 0.009