← Retour à la recherche de CVE

CVE-2026-64777

container

Description

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.

CVSS 4.3EPSS 0.232%Risque 0.44
Voir la source
Publication
2026-08-20 19:16:57
Versions concernées
<1.2.0
Type
Image Docker
Dernière modification
2026-08-27 20:09:53
Vecteur
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N