Description
Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
Published: 2026-10-07
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

If upgrading is not immediately possible, ensure that registry hostnames resolve only to trusted, non-loopback IP addresses. For example, administrators can use a trusted DNS configuration or a local hosts-file entry to pin the registry hostname to its expected address. Alternatively, restrict outbound network access from the Docker daemon so that registry connections can only reach trusted registry endpoints. Removing entries from the insecure-registries configuration is not sufficient, because Docker Engine automatically treats the 127.0.0.0/8 and ::1/128 ranges as insecure. Using a trusted CA certificate for the registry does not mitigate this issue if the registry hostname can also resolve to a loopback address, because the resulting registry configuration permits connections without certificate verification. As a defense in depth against image substitution, images can be referenced by digest rather than by a mutable tag. This does not prevent disclosure of registry credentials and should not be considered a complete workaround.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Docker
Docker docker Engine
Moby
Moby moby
Vendors & Products Docker
Docker docker Engine
Moby
Moby moby

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Docker Engine classifies a registry hostname as insecure using an any-match DNS check. loadInsecureRegistries() injects 127.0.0.0/8 and ::1/128 as insecure CIDRs by default. isCIDRMatch resolves all of the hostname's addresses and returns true if a single address is in the insecure CIDR list. Because the transport re-dials the hostname rather than the CIDR-matching address, a DNS answer set of one loopback IP plus a non-loopback attacker IP disables certificate verification and enables HTTP fallback for the registry connection.
Title Docker Engine insecure-registry fallback via malicious DNS responses
Weaknesses CWE-295
CWE-319
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-07T20:31:28.770Z

Reserved: 2026-09-16T13:00:33.499Z

Link: CVE-2026-92543

cve-icon Vulnrichment

Updated: 2026-10-07T20:31:22.747Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:02.727

Modified: 2026-10-07T21:17:21.813

Link: CVE-2026-92543

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T21:45:06Z

Weaknesses