Docker disclosed and fixed CVE-2026-79994, a high-severity time-of-check to time-of-use (TOCTOU) vulnerability in the host-side relay used by Docker Sandboxes. A malicious sandbox guest could alter an intermediate workspace directory after validation of a Unix-socket path, replacing it with a symbolic link and causing the trusted relay to connect to an AF_UNIX socket outside the approved workspace.
The flaw affects Docker Sandboxes versions 0.37.0 through versions before 0.41.0; version 0.41.0 includes the specific fix. Docker's broader security advisory recommends upgrading deployments to 0.43.0 or later. Although the issue does not directly grant unrestricted host filesystem access, it can enable a guest to influence connections to reachable host socket services, potentially affecting confidentiality and integrity; no active exploitation has been confirmed.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Docker published a security advisory concerning vulnerabilities affecting Docker Sandboxes releases earlier than version 0.43.0. The advisory recommended upgrading affected deployments, without providing CVE identifiers, severity ratings, technical details, or evidence of exploitation.
Docker fixed high-severity CVE-2026-79994 in the Docker Sandboxes host-side relay. The TOCTOU flaw affected versions 0.37.0 through versions before 0.41.0 and could let a malicious guest redirect the relay to an arbitrary reachable pathname-based Unix socket; version 0.41.0 contains the fix, and no active exploitation was confirmed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
linuxsecurity.com
Open sourcecirt.gy
Open sourcedocs.docker.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.