CVE-2026-78122: Tecnativa Docker-Socket-Proxy

High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

Affected products

  • Tecnativa Docker-Socket-Proxy: up to and including 0.5.0

Published 2026-08-22. Last modified 2026-09-24.