Description
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
Published: 2026-10-07
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: Bypass certificate validation and enable insecure HTTP registry connection, allowing image tampering and potential credential disclosure
Action: Implement Workaround
AI Analysis

Impact

Docker Engine treats any DNS address that falls within the insecure CIDR ranges 127.0.0.0/8 or ::1/128 as insecure and automatically disables certificate verification for that hostname. When a DNS response for a registry hostname includes both a loopback IP and an attacker‑controlled non‑loopback IP, the deep‑copy check succeeds for the loopback address, causing the transport to skip verification and fall back to plain HTTP. This can allow an attacker to supply or intercept registry traffic, distribute tampered images or harvest credentials from the Docker daemon.

Affected Systems

The vulnerability is documented for Docker Engine and the Moby project. No specific version numbers are listed, so all current releases that implement the insecure‑registry logic may be affected.

Risk and Exploitability

The CVSS score of 7.6 indicates high severity, and the lack of an EPSS score means the current exploitation probability is unknown but the problem remains significant. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector relies on the attacker being able to supply malicious DNS responses to the Docker daemon, a scenario that is plausible in shared or compromised DNS infrastructure. Once achieved, the attacker can bypass certificate verification, downgrade the connection to HTTP, and potentially inject malicious content or exfiltrate sensitive credentials.

Generated by OpenCVE AI on October 7, 2026 at 18:58 UTC.

Remediation

Vendor Workaround

If upgrading is not immediately possible, ensure that registry hostnames resolve only to trusted, non-loopback IP addresses. For example, administrators can use a trusted DNS configuration or a local hosts-file entry to pin the registry hostname to its expected address. Alternatively, restrict outbound network access from the Docker daemon so that registry connections can only reach trusted registry endpoints. Removing entries from the insecure-registries configuration is not sufficient, because Docker Engine automatically treats the 127.0.0.0/8 and ::1/128 ranges as insecure. Using a trusted CA certificate for the registry does not mitigate this issue if the registry hostname can also resolve to a loopback address, because the resulting registry configuration permits connections without certificate verification. As a defense in depth against image substitution, images can be referenced by digest rather than by a mutable tag. This does not prevent disclosure of registry credentials and should not be considered a complete workaround.


OpenCVE Recommended Actions

  • Ensure registry hostnames resolve only to trusted, non‑loopback IP addresses by configuring a trusted DNS server or pins the hostname to the expected IP via a hosts file.
  • Restrict the Docker daemon’s outbound network access so it can reach only trusted registry endpoints, blocking unintended DNS resolutions.
  • Use image references by digest rather than mutable tags to reduce the risk of image substitution, while noting that this does not mitigate credential disclosure.

Generated by OpenCVE AI on October 7, 2026 at 18:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
Title Docker Engine insecure-registry fallback via malicious DNS responses
Weaknesses CWE-295
CWE-319
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-07T18:27:34.058Z

Reserved: 2026-09-16T13:00:33.499Z

Link: CVE-2026-92543

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:02.727

Modified: 2026-10-07T17:17:02.727

Link: CVE-2026-92543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:00:16Z

Weaknesses
  • CWE-295

    Improper Certificate Validation

  • CWE-319

    Cleartext Transmission of Sensitive Information