CVE-2014-5282: Docker

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

Affected products

  • Docker Docker: before 1.3 (fixed in 1.3)

Published 2018-02-06. Last modified 2026-06-17.