ACVE-2026-0436
Docker Sandboxes below 0.42.0, running code from a sandboxed coding project, let guest code reach macOS host files or host-side Unix sockets outside the authorized workspace.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-77179 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Identifier CVE-2026-79994 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Fixed in 0.42.0 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Fixed in 4.88.0 | Detected | cveawg.mitre.org | |
| Severity CRITICAL; matches CNA | Confirmed | cveawg.mitre.org | 2026-09-24 |
In the wild
demonstrated
Description
What
Docker's security announcement describes two Docker Sandboxes flaws fixed in 0.42.0. One allowed guest code on macOS to access host files outside the shared workspace; the other allowed a guest to reach host-side Unix sockets outside that workspace.
Detection
Recorded from Docker's security announcement and the contemporaneous report. Not recreated in a lab.
Fix
Upgrade Docker Sandboxes to 0.42.0 or later; Docker recommends clone mode and avoiding read-write host mounts if an update is not possible.
Fix
Upgrade Docker Sandboxes to 0.42.0 or later and Docker Desktop to 4.88.0 or later.
- Upgrade
harness:docker-sandboxesto0.42.0. First release that fixes both Docker Sandboxes CVEs. Owner: operator - Upgrade
harness:docker-desktopto4.88.0. Fix stated by the reporter for Docker Desktop. Owner: operator