CVE-2026-79994

Published Sep 15, 2026

Last updated 11 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-79994 describes a vulnerability found in the guest-to-host Unix-domain socket relay within Docker Sandboxes. The flaw arises because the system first validates that a socket path is located within an authorized workspace, but then subsequently reconnects using the same pathname. This time-of-check to time-of-use (TOCTOU) vulnerability allows a malicious guest to exploit the brief interval between validation and reconnection. By replacing an intermediate directory with a symlink during this window, the guest can trick the host into connecting to an arbitrary AF_UNIX socket outside of the intended shared workspace. This could potentially lead to the exposure of data or host-side capabilities provided by the targeted socket.

Description
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlink between validation and connection, causing the host to connect to an arbitrary AF_UNIX socket outside the shared workspace. This can expose data or host-side capabilities provided by the targeted socket.
Source
security@docker.com
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

security@docker.com
CWE-367

Social media

Hype score
Not currently trending
  1. Docker issued warnings about symlink escapes (CVE-2026-77179) and TOCTOU race conditions in Unix sockets (CVE-2026-79994). Are your containers handling resource creation atomically? #Docker #CVE #TOCTOU #DevOps

    @Nishanth_KJ

    23 Sept 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 #devopsish https://t.co/umLKsEGtxy

    @ChrisShort

    21 Sept 2026

    331 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Docker Sandboxes (microVM layer for Claude Code / Codex / Cursor / Copilot / etc.) closed two macOS host escapes: • CVE-2026-77179 (CVSS 9.4): virtio-fs symlink race → read/modify arbitrary host files as the VMM user • CVE-2026-79994 (8.7): Unix-socket relay TOCTOU →

    @hazemomier

    20 Sept 2026

    167 Impressions

    0 Retweets

    5 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  4. 现在各家都在搞 sandbox,睡前顺手发两个高危漏洞, 大家也方便自查一下。 CVE-2026-77179 和 CVE-2026-79994,评分 9.4 和 8.7 , 正好在打 Docker Sandbox。 ​ ​当然,最近还有很多其他的,都没幸免 🤣 过些天看情况再

    @aiandcloud

    19 Sept 2026

    1189 Impressions

    1 Retweet

    7 Likes

    2 Bookmarks

    2 Replies

    0 Quotes

  5. Docker patched CVE-2026-77179 (CVSS 9.4), a Docker Sandboxes macOS escape via virtio-fs symlinks, and CVE-2026-79994. Update to 0.42.0+ to prevent guest code from reading/writing host files. Details: https://t.co/lEHjZhrtFI https://t.co/QC14eBVf0C #2workly

    @2Workly

    18 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Your AI agent's sandbox just became the escape hatch. Docker Sandboxes CVE-2026-77179 (Critical 9.4) + CVE-2026-79994 (High 8.7) let code inside the agent VM reach the macOS host. Fixed in 0.42.0. https://t.co/6O1TFji5Da https://t.co/O8S7do0q6x

    @aratech_social

    18 Sept 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 Docker Sandboxes has a serious security problem. Two vulnerabilities, CVE-2026-77179 and CVE-2026-79994, can break the isolation protecting AI coding agents and expose host-level files and Unix sockets. CVE-2026-77179 carries a CVSS 9.4 Critical rating. CVE-2026-79994 is

    @thecybersecguru

    18 Sept 2026

    184 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    1 Quote

  8. Sandbox nie jest magiczną granicą bezpieczeństwa. CVE-2026-77179 i CVE-2026-79994 pokazują, że kod agenta AI może przebić izolację Docker Sandboxes. Aktualizuj do 0.42.0+ i traktuj sandbox jak każdą inną warstwę security. #Docker #AI #Security https://t.co/y4HpY6

    @quietcodelife

    18 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Docker patched a critical macOS sandbox escape (CVE-2026-77179) and a high-severity socket relay flaw (CVE-2026-79994) in Sandboxes 0.42.0 on September 7. https://t.co/f6yLYKBPTl

    @brockerorg

    17 Sept 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🚨 Docker Sandboxes’ta ciddi açıklar bulundu! CVE-2026-77179 ve CVE-2026-79994, kötü amaçlı bir container’ın izole ortamdan çıkıp host sistemdeki hassas kaynaklara erişmesine yol açabiliyor. Açıklar 0.42.0 sürümünde kapatıldı. #Docker #CyberSecurity http

    @KubbeSiber

    17 Sept 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Vulnerabilidades críticas en Docker permiten escapar de microVMs aisladas Docker ha solucionado dos vulnerabilidades graves (CVE-2026-77179 y CVE-2026-79994) en Docker Sandboxes https://t.co/47aKd02VnG

    @elhackernet

    17 Sept 2026

    3747 Impressions

    7 Retweets

    34 Likes

    8 Bookmarks

    0 Replies

    0 Quotes

  12. Docker released an update for critical Docker Sandboxes vulnerabilities (CVE-2026-77179, CVE-2026-79994). Patch these Docker Sandboxes vulnerabilities today. #Docker #DockerSandboxes #CVE202677179 #CVE202679994 #Cybersecurity https://t.co/jai8yOriPY

    @Daily_CyberSec

    17 Sept 2026

    416 Impressions

    0 Retweets

    2 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  13. Docker security announcements | Docker Docs Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 https://t.co/ajvcO0VeJm

    @autumn_good_35

    16 Sept 2026

    407 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes