VendorsDockerengineany version
Vulnerabilities

Docker Engine any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-34040
Moby: AuthZ plugin bypass with oversized request body
Published 2026-03-31 · Analyzed
8.8EPSS 0.091
CVE-2026-33997
Moby: Off-by-one error in plugin privilege validation
Published 2026-03-31 · Modified
8.4EPSS 0.004
CVE-2026-42306
Moby: Race condition in docker cp allows bind mount redirection to host path
Published 2026-06-12 · Analyzed
7.2EPSS 0.001
CVE-2026-41568
Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Published 2026-06-12 · Analyzed
6.1EPSS 0.001
CVE-2020-13401
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Published 2020-06-02 · Modified
6.0EPSS 0.028
CVE-2018-20699
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
Published 2019-01-12 · Modified
4.9EPSS 0.022