๐Ÿ” CVE Alert

CVE-2026-78122

HIGH 7.4

docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems

CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
0th

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

CWE CWE-1220
Vendor tecnativa
Product docker-socket-proxy
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for tecnativa docker-socket-proxy

Be the first to know when new high vulnerabilities affecting tecnativa docker-socket-proxy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Tecnativa / docker-socket-proxy
0 โ‰ค 0.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Tecnativa/docker-socket-proxy/issues/182 github.com: https://github.com/Tecnativa/docker-socket-proxy github.com: https://github.com/Tecnativa/docker-socket-proxy/blob/v0.5.0/haproxy.cfg#L49-L61 github.com: https://github.com/Tecnativa/docker-socket-proxy/pull/183 gist.github.com: https://gist.github.com/nedlir/e4f52f88a757f02c67db1fd5dd70d732 vulncheck.com: https://www.vulncheck.com/advisories/docker-socket-proxy-through-insufficient-access-control-granularity-exposes-container-filesystems

Credits

๐Ÿ” nedlir