CVE-2025-4095: Docker Desktop

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Registry Access Management (RAM) is a security feature allowing administrators to restrict access for their developers to only allowed registries. When a MacOS configuration profile is used to enforce organization sign-in, the RAM policies are not being applied, which would allow Docker Desktop users to pull down unapproved, and potentially malicious images from any registry.

Affected products

  • Docker Docker Desktop: from 4.36.0, before 4.41.0 (fixed in 4.41.0)

Published 2025-04-29. Last modified 2026-06-17.