Vulnerability
Published 2026-10-01
Verified 2026-10-08

Docker Engine 29.8.2 fixes two flaws: a DNS answer mixing a loopback and an attacker IP can switch off TLS checks for a registry and leak credentials (CVE-2026-92543), and Swarm encrypted overlays accept forged VXLAN frames (CVE-2026-92542)

Docker published two Moby security advisories on 1 October 2026, with the CVE records following on 7 October; both are fixed in Docker Engine 29.8.2. CVE-2026-92543 (GHSA-7cfq-22r6-qp73, CVSS 4.0 score 7.6 High): Docker Engine always treats 127.0.0.0/8 and ::1/128 as insecure registry ranges, and it decides a registry is insecure if any one of the addresses its hostname resolves to falls in those ranges. Because the connection then re-dials the hostname rather than the matching address, an attacker who can shape DNS answers (one loopback address plus one of their own) can make the daemon skip certificate verification and allow plain-HTTP fallback, exposing registry credentials sent in X-Registry-Auth or substituting the image behind a trusted tag. Removing entries from insecure-registries does not help, and a trusted CA does not mitigate it. CVE-2026-92542 (GHSA-6m9p-4h64-m6vh, CVSS 4.0 score 6.9 Medium): on Linux Swarm nodes the firewall rules that mark VXLAN traffic for IPsec encryption also match datagrams forged by ordinary user processes, so an unprivileged local user can inject Ethernet frames into an encrypted overlay network on another node. No exploitation has been reported. Primary: Moby GitHub security advisories; listed on Tenable's newest CVE feed 8 Oct.

Product
Docker Engine (Moby), including Linux Swarm encrypted overlay networks
Versions
CVE-2026-92543: Docker Engine before 29.8.2 (moby/v2 before v2.0.0-beta.25). CVE-2026-92542: Docker Engine 25.0.18 and earlier and 26.0.0 to 29.8.1 (the docker/docker libnetwork overlay package is fixed in 25.0.19).
CVSS
(CVSS 4.0, CVE-2026-92543); 6.9 (CVSS 4.0, CVE-2026-92542)
Exploited in Australia?
unknown
Patch to
Upgrade Docker Engine to 29.8.2 or later. Until then, make registry hostnames resolve only to trusted, non-loopback addresses (trusted DNS or a hosts-file pin) and limit the daemon's outbound access to known registries; pin images by digest as defence in depth. On Swarm, block user processes from sending UDP to the data-path port with the iptables OUTPUT rule given in GHSA-6m9p-4h64-m6vh.

Primary: Moby (Docker) — GHSA-7cfq-22r6-qp73: insecure-registry fallback via malicious DNS responses, CVE-2026-92543 (1 Oct 2026) · Vendor: Moby (Docker) — GHSA-6m9p-4h64-m6vh: blind VXLAN injection into encrypted overlay networks, CVE-2026-92542 (1 Oct 2026) · CVE: CVE-2026-92543, CVE-2026-92542 · Tenable — CVE-2026-92543 (7 Oct 2026)

tech cloud network