Docker released security updates for CVE-2024-41110, a critical flaw in Docker Engine that can let attackers bypass authorization controls and potentially escalate privileges when AuthZ authorization plugins are enabled. The bug is a regression of an issue first addressed in 2019, but the earlier fix was not carried forward into newer Docker Engine releases starting with 19.03, leaving later versions exposed. Docker Desktop installations are also affected through the bundled engine.
The vulnerability can be exploited by sending a specially crafted Docker API request with Content-Length: 0, causing the daemon to pass the request to authorization plugins without the request body and potentially leading to incorrect allow decisions and command execution. Affected versions include Docker Engine before 23.0.14 and before 27.1.0, and Docker Desktop before 4.33; Mirantis Container Runtime and deployments not using AuthZ plugins are not impacted. Defenders were urged to update immediately or, if patching is not yet possible, disable AuthZ plugins and restrict Docker API access to trusted users and systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting described exploitation of the flaw as sending a specially crafted API request with Content-Length set to 0, causing the Docker daemon to forward the request to AuthZ plugins without the body. This can lead to incorrect authorization decisions and command execution.
Docker states that CVE-2024-41110 is a regression of an authorization bypass issue that had originally been fixed in January 2019. The earlier fix was not incorporated into newer Docker Engine versions 19.03 and later.
Docker released security updates to fix CVE-2024-41110, a critical Docker Engine vulnerability that can enable authorization bypass and privilege escalation when AuthZ plugins are in use. Affected versions include Docker Engine before 23.0.14 and before 27.1.0, and Docker Desktop before 4.33.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.