Sensitive Information Exposure in Docker Desktop by Docker
CVE-2025-3911
What is CVE-2025-3911?
A vulnerability in the Docker Desktop application allows for the logging of environment variables configured for running containers. This can result in the unintentional disclosure of sensitive information, such as API keys and passwords, within the application logs. If an unauthorized user gains access to these logs, they could exploit this information to gain further access to other systems or services. To mitigate this risk, Docker has implemented changes starting with version 4.41.0, which prevents the logging of user-defined environment variables.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Docker Desktop Windows 0 < 4.41.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
