CVE-2014-9358: Docker

Medium severity, CVSS 6.4. EPSS: 2.5% chance of exploitation in the next 30 days.

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

Affected products

  • Docker Docker: up to and including 1.3.2

Published 2014-12-16. Last modified 2026-06-17.