CVE-2026-44985·Docker vulnerability
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sibling subdomain, or another service on localhost) can initiate a WebSocket connection to the exec endpoint that carries the victim's valid JWT cookie, gaining interactive shell access in any container the victim is authorized to access. This vulnerability is fixed in 10.5.2.
- Severity
- critical
- Software
- Docker
- Fixed in
- 10.5.2
- Published
- 2026-05-26
Affected versions
Until: 10.5.2
Fixed in: 10.5.2
How to fix this CVE
Update Docker to version 10.5.2 or later to remediate this critical WebSocket origin validation vulnerability. The fix enforces proper CORS origin checking on the /exec and /attach endpoints and strengthens JWT cookie security policies. Administrators should prioritize this update immediately given the CVSS 9.6 severity rating and the potential for unauthorized container shell access.
sudo dnf update docker-ceDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /exec HTTP/1.1
Upgrade: websocket
Connection: Upgrade
Origin: http://attacker.example.com
Cookie: jwt_token=eyJ.*
OR
GET /attach?.*container_id HTTP/1.1
Upgrade: websocket
Connection: Upgrade
Sec-WebSocket-Key: .*WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule that blocks WebSocket upgrade requests to /exec and /attach endpoints unless the Origin header matches the exact host header value. Additionally, enforce SameSite=Strict on all authentication cookies and require explicit CORS whitelisting before processing WebSocket upgrade requests.How to check if you are affected
- Run `docker --version` to identify the currently installed Docker version; versions below 10.5.2 are vulnerable
- Check if Dozzle is deployed by running `docker ps | grep dozzle` or examining Docker Compose/Kubernetes manifests for Dozzle containers
- Review Docker daemon logs and reverse proxy access logs for suspicious WebSocket upgrade requests to /exec or /attach endpoints from unexpected origins: `sudo journalctl -u docker -n 100 --grep WebSocket`
- After updating, verify the new version with `docker --version` and restart the Docker daemon: `sudo systemctl restart docker`
FAQ
What is CVE-2026-44985?
CVE-2026-44985 is a critical authentication bypass vulnerability in Docker's WebSocket implementation that allows attackers from same-site origins to establish authenticated connections to container shell endpoints without proper origin validation, enabling unauthorized container access.
Is CVE-2026-44985 being actively exploited?
No. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are available at this time.
What versions of Docker are affected by CVE-2026-44985?
All Docker versions prior to 10.5.2 are affected. Version 10.5.2 and later contain the necessary security fixes.
How do I check if my server is vulnerable to CVE-2026-44985?
Run `docker --version` and compare the output to version 10.5.2. If your version is lower, your deployment is vulnerable. Additionally, verify Dozzle is not running with `docker ps | grep dozzle`.
Does Defensia detect CVE-2026-44985?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-44985 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-44985. Free for 1 server.
Get started free