CVE-2026-78122 HIGH

CVE-2026-78122: docker-socket-proxy through 0.5.0 Insufficient Access Control Granularity Exposes Container Filesystems

Vendor Tecnativa
Product docker-socket-proxy
Weakness CWE-1220
Published August 22, 2026
Last update August 29, 2026

CVSS base score

8.3/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

Key dates

02Disclosure timeline

August 22, 2026 CVE published
August 29, 2026 Record updated