{"id":"CVE-2026-78122","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-78122","summary":"docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to…","details":"docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.","published":"2026-08-22T23:16:22.923","modified":"2026-08-22T23:16:22.923","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/Tecnativa/docker-socket-proxy/pull/183","label":"Tecnativa/docker-socket-proxy#183"},"references":[{"type":"WEB","url":"https://gist.github.com/nedlir/e4f52f88a757f02c67db1fd5dd70d732"},{"type":"WEB","url":"https://github.com/Tecnativa/docker-socket-proxy"},{"type":"WEB","url":"https://github.com/Tecnativa/docker-socket-proxy/blob/v0.5.0/haproxy.cfg#L49-L61"},{"type":"WEB","url":"https://github.com/Tecnativa/docker-socket-proxy/issues/182"},{"type":"WEB","url":"https://github.com/Tecnativa/docker-socket-proxy/pull/183"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/docker-socket-proxy-through-insufficient-access-control-granularity-exposes-container-filesystems"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T23:16:22.923"}}