Impact
Docker Engine treats any DNS address that falls within the insecure CIDR ranges 127.0.0.0/8 or ::1/128 as insecure and automatically disables certificate verification for that hostname. When a DNS response for a registry hostname includes both a loopback IP and an attacker‑controlled non‑loopback IP, the deep‑copy check succeeds for the loopback address, causing the transport to skip verification and fall back to plain HTTP. This can allow an attacker to supply or intercept registry traffic, distribute tampered images or harvest credentials from the Docker daemon.
Affected Systems
The vulnerability is documented for Docker Engine and the Moby project. No specific version numbers are listed, so all current releases that implement the insecure‑registry logic may be affected.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, and the lack of an EPSS score means the current exploitation probability is unknown but the problem remains significant. The vulnerability is not listed in CISA’s KEV catalog, but the attack vector relies on the attacker being able to supply malicious DNS responses to the Docker daemon, a scenario that is plausible in shared or compromised DNS infrastructure. Once achieved, the attacker can bypass certificate verification, downgrade the connection to HTTP, and potentially inject malicious content or exfiltrate sensitive credentials.
OpenCVE Enrichment