CVE-2026-78122Disclosure

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1220

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-08-22); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-22: 2Mentions · 2026-08-23: 1Mentions · 2026-08-24: 1Mentions · 2026-08-31: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-31: 1Technical Details · 2026-08-22: 2Technical Details · 2026-08-23: 1Technical Details · 2026-08-24: 1Technical Details · 2026-08-31: 108-2208-2308-2408-31
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-222
Disclosure2
2026-08-231
General1
2026-08-241
Disclosure1
2026-08-311
Patch1
Full discourse5 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2026-78122 (CVSS 7.4) docker-socket-proxy fails to gate read endpoints. Attackers can extract container filesystems via GET requests when CONTAINERS env var is set. Patch immediately. #CVE #Vulnerability #PatchNow #Docker https://t.co/AGjvquplHc

    Post summary

    The tweet highlights CVE-2026-78122 in docker-socket-proxy, a high‑severity flaw that lets attackers read container filesystems, and urges an immediate patch.

    0000046
    121 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-78122 - Arbitrary file read in docker-socket-proxy allows leaks of container filesystems and logs. CVSS 7.4. Review and restrict proxy access now. #CVE #Docker #infosec https://www.valtersit.com/cve/CVE-2026-78122 #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #china #france #germany

    Post summary

    The post announces CVE-2026-78122, an arbitrary file‑read vulnerability in docker‑socket‑proxy (CVSS 7.4), and recommends restricting proxy access as a mitigation step.

    0000061
    1.0K followersView on X
  • ADK Cyber@ADKCyber
    General

    CVE-2026-78122 (CVSS 8.3) affects docker-socket-proxy, exposing Docker container read endpoints when CONTAINERS env var is set. Assess exposure if using this tool. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/jo7cGvEONO

    Post summary

    The tweet highlights CVE-2026-78122 with its CVSS score and technical detail that docker‑socket‑proxy exposes read endpoints when the CONTAINERS environment variable is set, but it does not mention PoC, exploit code, or a patch.

    0000044
    93 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-78122 docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use G… https://www.cve.org/CVERecord?id=CVE-2026-78122 ----- Traducción: CVE-2026-78122 doc… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-78122, describing a misuse of the docker-socket-proxy’s gating of Docker API read endpoints when the CONTAINERS variable is set; no PoC, exploit code, or patch is mentioned.

    0000030
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-78122 docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use G… https://www.cve.org/CVERecord?id=CVE-2026-78122

    Post summary

    CVE‑2026‑78122 exposes a misconfiguration in docker‑socket‑proxy that allows attackers to read endpoints in the /containers API namespace when the CONTAINERS environment variable is set.

    000001.6K
    58.0K followersView on X

Explore more