CVE-2026-92543
Received Received - Intake

Docker Engine Insecure Registry Hostname DNS Spoofing

Vulnerability report for CVE-2026-92543, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Docker Inc.

Description

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Docker Docker Engine 0
Moby Moby 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Docker Engine incorrectly treats registry hostnames as insecure if their DNS response includes any loopback IP (127.0.0.0/8 or ::1/128), even alongside malicious non-loopback IPs. This causes certificate verification to be disabled and forces HTTP fallback for registry connections, allowing attackers to intercept credentials or substitute trusted images.

Detection Guidance

Check Docker Engine version with 'docker version' or 'dockerd --version'. If below 29.8.2, the system is vulnerable. Inspect DNS responses for registry hostnames to see if loopback IPs (127.0.0.0/8 or ::1/128) are included alongside other IPs. Monitor registry connections for unexpected HTTP fallback instead of HTTPS.

Impact Analysis

An attacker could exploit this to intercept registry credentials sent via X-Registry-Auth or replace trusted image tags with malicious ones. This could lead to unauthorized access to sensitive data or execution of malicious code.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face compliance violations and legal consequences.

Mitigation Strategies

Upgrade Docker Engine to version 29.8.2 or later immediately. If upgrading is not possible, ensure registry hostnames resolve only to trusted, non-loopback IPs by using trusted DNS or local hosts-file entries. Restrict outbound network access from the Docker daemon to prevent malicious DNS manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92543. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart