CVE-2026-92543: Docker Engine

High severity, CVSS 7.6. EPSS: 0.1% chance of exploitation in the next 30 days.

Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.

Affected products

  • Docker Docker Engine: before 29.8.2 (fixed in 29.8.2)
  • Moby Moby: before v2.0.0-beta.25 (fixed in v2.0.0-beta.25)

Published 2026-10-07. Last modified 2026-10-08.