Docker Desktop
40 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Docker Desktop, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
Docker Desktop CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 3 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 3 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 40 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High22
- Medium9
Latest CVEs
The 15 most recently published vulnerabilities affecting Docker Desktop.
- CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link following—
- CVE-2026-8936Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM—
- CVE-2026-5843Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading8.2
- CVE-2026-5817Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends8.2
- CVE-2026-6406Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag8.8
- CVE-2026-2664Out of bounds read vulnerability in grpcfuse kernel module7.8
- CVE-2025-14740Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities6.7
- CVE-2025-13743Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs7.5
- CVE-2025-9164Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows7.8
- CVE-2025-10657Docker Desktop with ECI Fails to Enforce Socket Command Restrictions—
- CVE-2025-9074Docker Desktop allows unauthenticated access to Docker Engine API from containers8.6
- CVE-2025-6587Exposure of system environment variables in Docker Desktop diagnostic logs6.5
- CVE-2025-3911Exposure in Docker Desktop logs of environment variables configured for running containers—
- CVE-2025-4095Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile—
- CVE-2025-3224Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion7.8
Product grouping is registry-driven, with AI assist and human review. How it works