PT-2026-107624 · Docker · Moby+1
CVSS v4.0
7.6
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Docker Engine versions prior to 29.8.2
Moby versions prior to 2.0.0-beta.25
Description
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. The
loadInsecureRegistries() function injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. The isCIDRMatch() function resolves all addresses for a hostname and returns true if any single address is within the insecure CIDR list. Since the transport re-dials the hostname instead of the specific CIDR-matching address, a DNS response containing both a loopback IP and an attacker-controlled IP disables certificate verification and enables HTTP fallback for the registry connection. This allows an attacker who can influence DNS to skip TLS certificate verification and force a fallback to HTTP, potentially exposing registry credentials and enabling image substitution.Recommendations
Update Docker Engine to version 29.8.2.
Update Moby to version 2.0.0-beta.25.
Fix
Cleartext Transmission of Sensitive Information
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docker Engine
Moby