๐Ÿ” CVE Alert

CVE-2026-92543

UNKNOWN 0.0

Docker Engine insecure-registry fallback via malicious DNS responses

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

CWE CWE-295 CWE-319
Vendor docker
Product docker engine
Ecosystems
Industries
Technology
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for docker docker engine

Be the first to know when new unknown vulnerabilities affecting docker docker engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Docker / Docker Engine
0 < 29.8.2
Moby / Moby
0 < v2.0.0-beta.25

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73

Credits

Adam Korczynski of ADA Logics