Socket Relay Vulnerability in Docker Sandbox Products
CVE-2026-79994
Key Information:
- Vendor
Docker
- Status
- Vendor
- CVE Published:
- 15 September 2026
Badges
What is CVE-2026-79994?
A vulnerability exists in Docker Sandboxes where the guest-to-host Unix-domain socket relay fails to securely validate socket paths. Although it checks that the path is within an authorized workspace, it subsequently reconnects using the provided pathname. An attacker on the guest can exploit this by replacing an intermediate directory with a symlink, leading the host to inadvertently connect to an arbitrary AF_UNIX socket outside the intended shared workspace. This could potentially expose sensitive data or capabilities of the host system that are accessible through the targeted socket.
Affected Version(s)
Docker Sandboxes 0.37.0 < 0.42.0
News Articles
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Docker Sandboxes flaws can expose host files or Unix sockets outside the workspace; both were fixed in 0.42.0, with no exploitation reported
3 weeks ago
Critical Docker Sandbox Vulnerabilities Enable Malicious Guests to Escape Isolated microVM Workspaces
Docker patched two serious Sandbox vulnerabilities that could let malicious guest workloads escape their isolated workspace and access sensitive host resources.
3 weeks ago

References
CVSS V4
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Cybersecuritynews
Vulnerability published
Vulnerability Reserved
