GHSA-gxmj-gjp2-h2mvHighCVSS 7.4

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace...

Published
August 23, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (1)

📋 Description

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

🔗 References (8)