CVE Tools

Docker Desktop

40 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Docker Desktop, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Docker Desktop CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Docker Desktop CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-031
2025-043
2025-050
2025-060
2025-071
2025-081
2025-091
2025-101
2025-110
2025-121
2026-010
2026-022
2026-030
2026-040
2026-053
2026-061
2026-070
2026-081
2026-090

Severity

How the 40 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical39%
  • High2265%
  • Medium926%

Latest CVEs

The 15 most recently published vulnerabilities affecting Docker Desktop.

  1. CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link following—
  2. CVE-2026-8936Unbounded recursion in grpcfuse kernel module allows container to crash Docker Desktop VM—
  3. CVE-2026-5843Docker Model Runner container-to-host code execution via MLX-LM model_file importlib loading8.2
  4. CVE-2026-5817Docker Model Runner container-to-host code execution via unsandboxed trust_remote_code in Python inference backends8.2
  5. CVE-2026-6406Docker Desktop Enhanced Container Isolation bypass via --use-api-socket CLI flag8.8
  6. CVE-2026-2664Out of bounds read vulnerability in grpcfuse kernel module7.8
  7. CVE-2025-14740Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities6.7
  8. CVE-2025-13743Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs7.5
  9. CVE-2025-9164Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows7.8
  10. CVE-2025-10657Docker Desktop with ECI Fails to Enforce Socket Command Restrictions—
  11. CVE-2025-9074Docker Desktop allows unauthenticated access to Docker Engine API from containers8.6
  12. CVE-2025-6587Exposure of system environment variables in Docker Desktop diagnostic logs6.5
  13. CVE-2025-3911Exposure in Docker Desktop logs of environment variables configured for running containers—
  14. CVE-2025-4095Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile—
  15. CVE-2025-3224Elevation of Privilege in Docker Desktop for Windows during Upgrade due to Insecure Directory Deletion7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store