critical CVSS 9.8

CVE-2025-34221·Docker vulnerability

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 25.2.1518 (VA/SaaS deployments) expose every internal Docker container to the network because firewall rules allow unrestricted traffic to the Docker bridge network. Because no authentication, ACL or client‑side identifier is required, the attacker can interact with any internal API, bypassing the product’s authentication mechanisms entirely. The result is unauthenticated remote access to internal services, allowing credential theft, configuration manipulation and potential remote code execution. This vulnerability has been identified by the vendor as: V-2025-002 — Authentication Bypass - Docker Instances.

Severity
critical
Software
Docker
Fixed in
25.2.169
Published
2025-09-29

Affected versions

Until: 25.2.169

Fixed in: 25.2.169

How to fix this CVE

Upgrade Docker to version 25.2.169 or later to patch the Docker bridge network firewall misconfiguration that allows unauthenticated access to internal containers. This critical vulnerability bypasses authentication entirely by exposing internal APIs through unrestricted network access. Apply the update immediately across all affected systems and verify firewall rules are properly configured to restrict Docker bridge access.

sudo dnf update docker-ce

Defensia detects this vulnerability

How to check if you are affected

  1. Step 1: Run `docker --version` or `docker -v` to check your installed Docker version and confirm if it is below 25.2.169
  2. Step 2: Execute `sudo iptables -L -n -v | grep -i docker` to review current firewall rules on the Docker bridge interface (docker0) and check for unrestricted access rules
  3. Step 3: Search Docker daemon logs with `sudo journalctl -u docker -n 500 --no-pager | grep -i 'bridge\|network\|unauthorized'` for signs of unusual internal API access attempts
  4. Step 4: After patching, run `docker --version` again and verify the version is 25.2.169 or higher, then confirm Docker daemon has restarted with `sudo systemctl status docker`

FAQ

What is CVE-2025-34221?

CVE-2025-34221 is a critical authentication bypass flaw in Docker where misconfigured firewall rules expose internal Docker containers to network access without requiring credentials, allowing attackers to interact with internal APIs, steal credentials, and execute arbitrary code.

Is CVE-2025-34221 being actively exploited?

According to CISA's Known Exploited Vulnerabilities (KEV) list, CVE-2025-34221 is not currently being actively exploited in the wild, and no public exploits are available yet.

What versions of Docker are affected by CVE-2025-34221?

All Docker versions prior to 25.2.169 are vulnerable. The exact lower bound of affected versions is unknown, but Docker 25.2.169 and all later versions contain the necessary firewall rule fixes.

How do I check if my server is vulnerable to CVE-2025-34221?

Run `docker --version` to check your version number. If the output shows a version lower than 25.2.169, your system is vulnerable. Additionally, run `sudo iptables -L -n -v | grep docker` to inspect Docker bridge firewall rules and verify they are restrictive rather than permissive.

Does Defensia detect CVE-2025-34221?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2025-34221 will appear in your dashboard with remediation steps.

Related Docker CVEs

CVE-2026-57572CVSS 10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary command execution. This issue is fixed in version 0.9.0.
CVE-2026-26216CVSS 10Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing unauthenticated remote attackers to import arbitrary modules and execute system commands. Successful exploitation allows full server compromise, including arbitrary command execution, file read and write access, sensitive data exfiltration, and lateral movement within internal networks.
CVE-2026-44329CVSS 10free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management route group without OAuth2/bearer-token authorization middleware. A network attacker who can reach SMF on the SBI can hit UPI endpoints with no Authorization header at all, and the requests reach the SMF business handlers. In the running Docker lab this was directly demonstrated for read (GET /upi/v1/upNodesLinks), write (POST /upi/v1/upNodesLinks with attacker-controlled UP-node and link payload), and delete (DELETE /upi/v1/upNodesLinks/{nodeID}) operations. This vulnerability is fixed in 4.2.2.
CVE-2026-42298CVSS 10Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker-build.yml) allows any unauthenticated user to execute arbitrary code during the Docker build process and exfiltrate a highly privileged GITHUB_TOKEN (write-all permissions). This can be achieved simply by opening a Pull Request from a fork with a maliciously modified Dockerfile.dev. This issue has been patched via commit da44801.
CVE-2026-40281CVSS 10Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate arguments, allowing injection of arbitrary ExifTool pseudo-tags such as -FileName, -Directory, -SymLink, and -HardLink. This is a bypass of the incomplete key-sanitization fix introduced in v8.30.1. An unauthenticated attacker can rename or move any PDF being processed to an arbitrary path in the container filesystem, overwrite arbitrary files, or create symlinks and hard links at arbitrary paths.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-34221. Free for 1 server.

Get started free