CVE-2026-78122
docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.
| CWE | CWE-1220 |
| Vendor | tecnativa |
| Product | docker-socket-proxy |
| Published | Aug 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for tecnativa docker-socket-proxy
Be the first to know when new high vulnerabilities affecting tecnativa docker-socket-proxy are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Tecnativa / docker-socket-proxy
0 โค 0.5.0
References
github.com: https://github.com/Tecnativa/docker-socket-proxy/issues/182 github.com: https://github.com/Tecnativa/docker-socket-proxy github.com: https://github.com/Tecnativa/docker-socket-proxy/blob/v0.5.0/haproxy.cfg#L49-L61 github.com: https://github.com/Tecnativa/docker-socket-proxy/pull/183 gist.github.com: https://gist.github.com/nedlir/e4f52f88a757f02c67db1fd5dd70d732 vulncheck.com: https://www.vulncheck.com/advisories/docker-socket-proxy-through-insufficient-access-control-granularity-exposes-container-filesystems
Credits
๐ nedlir