Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If upgrading is not immediately possible, ensure that registry hostnames resolve only to trusted, non-loopback IP addresses. For example, administrators can use a trusted DNS configuration or a local hosts-file entry to pin the registry hostname to its expected address. Alternatively, restrict outbound network access from the Docker daemon so that registry connections can only reach trusted registry endpoints. Removing entries from the insecure-registries configuration is not sufficient, because Docker Engine automatically treats the 127.0.0.0/8 and ::1/128 ranges as insecure. Using a trusted CA certificate for the registry does not mitigate this issue if the registry hostname can also resolve to a loopback address, because the resulting registry configuration permits connections without certificate verification. As a defense in depth against image substitution, images can be referenced by digest rather than by a mutable tag. This does not prevent disclosure of registry credentials and should not be considered a complete workaround.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Docker
Docker docker Engine Moby Moby moby |
|
| Vendors & Products |
Docker
Docker docker Engine Moby Moby moby |
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection. | |
| Title | Docker Engine insecure-registry fallback via malicious DNS responses | |
| Weaknesses | CWE-295 CWE-319 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-07T20:31:28.770Z
Reserved: 2026-09-16T13:00:33.499Z
Link: CVE-2026-92543
Updated: 2026-10-07T20:31:22.747Z
Status : Received
Published: 2026-10-07T17:17:02.727
Modified: 2026-10-07T21:17:21.813
Link: CVE-2026-92543
No data.
OpenCVE Enrichment
Updated: 2026-10-07T21:45:06Z