CVE-2025-13743: Docker Desktop
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.
Affected products
- Docker Docker Desktop: from 4.51.0, before 4.54.0 (fixed in 4.54.0)
Published 2025-12-09. Last modified 2026-06-17.