PT-2026-107624 · Docker · Moby+1

·

CVE-2026-92543

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

7.6

High

VectorAV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Docker Engine versions prior to 29.8.2 Moby versions prior to 2.0.0-beta.25
Description Docker Engine classifies a registry hostname as insecure using an any-match DNS check. The loadInsecureRegistries() function injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. The isCIDRMatch() function resolves all addresses for a hostname and returns true if any single address is within the insecure CIDR list. Since the transport re-dials the hostname instead of the specific CIDR-matching address, a DNS response containing both a loopback IP and an attacker-controlled IP disables certificate verification and enables HTTP fallback for the registry connection. This allows an attacker who can influence DNS to skip TLS certificate verification and force a fallback to HTTP, potentially exposing registry credentials and enabling image substitution.
Recommendations Update Docker Engine to version 29.8.2. Update Moby to version 2.0.0-beta.25.

Fix

Cleartext Transmission of Sensitive Information

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92543

Affected Products

Docker Engine
Moby