CVE Explorer
CVE-2026-12539
Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-apply it to networks rebuilt from disk when the Docker daemon restarts, so a restart-surviving sandbox forwards ICMP to arbitrary hosts. A workload inside a sandbox, which the threat model treats as untrusted, can therefore defeat the documented ICMP egress block to perform network reconnaissance and exfiltrate data over an ICMP covert channel, regardless of the configured allowlis
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-665","description":"CWE-665: Improper Initialization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-923","description":"CWE-923: Improper Restriction of Communication Channel to Intended Endpoints","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"cpes":["cpe:2.3:a:docker:sandboxes:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","platforms":["MacOS","Linux","Windows"],"product":"Docker Sandboxes","vendor":"Docker","versions":[{"lessThan":"0.33.0","status":"affected","version":"0.14.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":5.1,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-665","description":"CWE-665: Improper Initialization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-923","description":"CWE-923: Improper Restriction of Communication Channel to Intended Endpoints","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["product"],"url":"https://docs.docker.com/ai/sandboxes/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/references/0
{"tags":["release-notes"],"url":"https://github.com/docker/sbx-releases/releases/tag/v0.33.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f41fe6f7475eaa987e679f2a921b36ed60c905f81bddee791427559c18800e97 · sha256:9196db0c2940b1a8… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.