Security Flaw in Docker Engine Affects Registry Connection
CVE-2026-92543

7.6HIGH

Key Information:

Vendor

Docker

Vendor
CVE Published:
7 October 2026

What is CVE-2026-92543?

A security vulnerability in Docker Engine occurs when it erroneously classifies a registry hostname as insecure due to an any-match DNS check. The loadInsecureRegistries() function by default injects loopback addresses as insecure CIDRs. Consequently, the isCIDRMatch function resolves all addresses of the hostname and returns true if any match the insecure list. This process allows the transport mechanism to revert to insecure connections, thus circumventing certificate verification and enabling HTTP fallback, which may expose the system to potential exploits and unauthorized access.

Affected Version(s)

Docker Engine 0 < 29.8.2

Moby 0

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.