Socket Relay Vulnerability in Docker Sandbox Products
CVE-2026-79994

8.7HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
15 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-79994?

A vulnerability exists in Docker Sandboxes where the guest-to-host Unix-domain socket relay fails to securely validate socket paths. Although it checks that the path is within an authorized workspace, it subsequently reconnects using the provided pathname. An attacker on the guest can exploit this by replacing an intermediate directory with a symlink, leading the host to inadvertently connect to an arbitrary AF_UNIX socket outside the intended shared workspace. This could potentially expose sensitive data or capabilities of the host system that are accessible through the targeted socket.

Affected Version(s)

Docker Sandboxes 0.37.0 < 0.42.0

News Articles

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Docker Sandboxes flaws can expose host files or Unix sockets outside the workspace; both were fixed in 0.42.0, with no exploitation reported

3 weeks ago

Critical Docker Sandbox Vulnerabilities Enable Malicious Guests to Escape Isolated microVM Workspaces

Docker patched two serious Sandbox vulnerabilities that could let malicious guest workloads escape their isolated workspace and access sensitive host resources.

3 weeks ago

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jurre van Bergen of ThreatNotify
.