CVE-2026-78122

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 23:16

Updated : 2026-08-26 18:17


NVD link : CVE-2026-78122

Mitre link : CVE-2026-78122

CVE.ORG link : CVE-2026-78122


JSON object : View

Products Affected

No product.

CWE
CWE-1220

Insufficient Granularity of Access Control