Docker Engine 29.8.2 fixes DNS trick that disables TLS checks
EditorialBy TrustList Editorial
The flaw sits in how the daemon decides a registry is insecure, so removing entries from insecure-registries does not help. Docker names three workarounds for teams that cannot upgrade yet.
- Docker
- Container Management
- DevOps
- Cybersecurity
- +1 more
About Docker Engine 29.8.2 fixes DNS trick that disables TLS checks
Docker Engine 29.8.2 fixes DNS trick that disables TLS checks
1 October 2026: Docker Engine before 29.8.2 can be tricked by a crafted DNS answer into talking to a registry without certificate verification. The flaw is CVE-2026-92543, rated high with a CVSS v4.0 score of 7.6, and the Moby project has fixed it in Docker Engine 29.8.2 and in the Go module github.com/moby/moby/v2 v2.0.0-beta.25. The advisory lists no exploitation in the wild. Italy's national cybersecurity agency, ACN, issued its own alert on 8 October pointing to the Moby advisory.
How the flaw works
When the daemon connects to a registry, it resolves the hostname and checks every address it gets back against its list of insecure ranges. By default that list contains 127.0.0.0/8 and ::1/128. If any one address falls inside an insecure range, the whole hostname is treated as insecure. The transport then dials the hostname rather than the address that matched.
An attacker who controls DNS for a registry name can therefore return two addresses: one loopback address and one pointing at a machine they run. The daemon treats the registry as insecure, skips certificate validation and allows a fall back to plain HTTP. The advisory describes two consequences. Registry credentials passed in the X-Registry-Auth header could reach the attacker's host, which can present an invalid certificate and still be accepted. And a trusted image tag could be replaced by the attacker's manifest and layers in the local image store.
The attack complexity is rated high and needs some user interaction, which is why the score stops at 7.6, but the confidentiality and integrity impact on the affected system is rated high.
Fixed versions
- Docker Engine 29.8.2 or later
- github.com/moby/moby/v2 v2.0.0-beta.25 or later, for software that embeds the Go module
If you cannot upgrade today
Two details in the advisory are easy to get wrong. Deleting entries from the insecure-registries setting does nothing, because the loopback ranges count as insecure regardless. And using a private certificate authority does not help either if the hostname can be made to resolve to a loopback address.
The workarounds Docker lists are to make registry hostnames resolve only to trusted, non-loopback addresses, for example through trusted DNS or pinned hosts-file entries; to restrict the daemon's outbound network access to known registry endpoints; and to pull images by digest instead of mutable tags. Digest pinning only limits image substitution. It does not stop credentials leaking.
The Moby project credits the report to AdamKorcz, and the advisory was published on 1 October 2026.
Company profile on TrustList: Docker
Related on TrustList:
Sources
- Moby project: GHSA-7cfq-22r6-qp73 security advisory, 1 October 2026
- Italy ACN: Risolta vulnerabilita in Docker Engine, 8 October 2026
Categories & features
- Docker
- Container Management
- DevOps
- Cybersecurity
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More DockerThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.