Skip to content
TrustList
News

Docker Engine 29.8.2 fixes DNS trick that disables TLS checks

Editorial

By TrustList Editorial

The flaw sits in how the daemon decides a registry is insecure, so removing entries from insecure-registries does not help. Docker names three workarounds for teams that cannot upgrade yet.

About Docker Engine 29.8.2 fixes DNS trick that disables TLS checks

Docker Engine 29.8.2 fixes DNS trick that disables TLS checks

1 October 2026: Docker Engine before 29.8.2 can be tricked by a crafted DNS answer into talking to a registry without certificate verification. The flaw is CVE-2026-92543, rated high with a CVSS v4.0 score of 7.6, and the Moby project has fixed it in Docker Engine 29.8.2 and in the Go module github.com/moby/moby/v2 v2.0.0-beta.25. The advisory lists no exploitation in the wild. Italy's national cybersecurity agency, ACN, issued its own alert on 8 October pointing to the Moby advisory.

How the flaw works

When the daemon connects to a registry, it resolves the hostname and checks every address it gets back against its list of insecure ranges. By default that list contains 127.0.0.0/8 and ::1/128. If any one address falls inside an insecure range, the whole hostname is treated as insecure. The transport then dials the hostname rather than the address that matched.

An attacker who controls DNS for a registry name can therefore return two addresses: one loopback address and one pointing at a machine they run. The daemon treats the registry as insecure, skips certificate validation and allows a fall back to plain HTTP. The advisory describes two consequences. Registry credentials passed in the X-Registry-Auth header could reach the attacker's host, which can present an invalid certificate and still be accepted. And a trusted image tag could be replaced by the attacker's manifest and layers in the local image store.

The attack complexity is rated high and needs some user interaction, which is why the score stops at 7.6, but the confidentiality and integrity impact on the affected system is rated high.

Fixed versions

  • Docker Engine 29.8.2 or later
  • github.com/moby/moby/v2 v2.0.0-beta.25 or later, for software that embeds the Go module

If you cannot upgrade today

Two details in the advisory are easy to get wrong. Deleting entries from the insecure-registries setting does nothing, because the loopback ranges count as insecure regardless. And using a private certificate authority does not help either if the hostname can be made to resolve to a loopback address.

The workarounds Docker lists are to make registry hostnames resolve only to trusted, non-loopback addresses, for example through trusted DNS or pinned hosts-file entries; to restrict the daemon's outbound network access to known registry endpoints; and to pull images by digest instead of mutable tags. Digest pinning only limits image substitution. It does not stop credentials leaking.

The Moby project credits the report to AdamKorcz, and the advisory was published on 1 October 2026.

Company profile on TrustList: Docker

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy