<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Docker — PoC Archive</title><link>https://poc.intelseclab.com/tags/docker/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/docker/index.xml" rel="self" type="application/rss+xml"/><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-20896 (GHSA-f75j-4cw6-rmx4). Status: Weaponized (public PoC + detector script, actively exploited in the wild per Sysdig). Affects: Gitea — official Docker images (gitea/gitea), both root and rootless variants. Tags: gitea, docker, authentication-bypass, reverse-proxy, header-spoofing, unauthenticated, remote, cwe-290, actively-exploited.</description><category>web</category><category>Critical</category><category>gitea</category><category>docker</category><category>authentication-bypass</category><category>reverse-proxy</category><category>header-spoofing</category><category>unauthenticated</category><category>remote</category><category>cwe-290</category><category>actively-exploited</category></item><item><title>Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41243-spring-cloud-gateway-actuator-rce-lab/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41243-spring-cloud-gateway-actuator-rce-lab/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-41243. Status: PoC. Affects: Spring Cloud Gateway (spring-cloud-starter-gateway 4.1.0 on spring-boot-starter-parent 3.3.0), with Actuator's gateway endpoint exposed. Tags: spring-cloud-gateway, actuator, spel-injection, rce, java, docker, lab-environment.</description><category>web</category><category>Critical</category><category>spring-cloud-gateway</category><category>actuator</category><category>spel-injection</category><category>rce</category><category>java</category><category>docker</category><category>lab-environment</category></item><item><title>RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</guid><description>Critical severity (CVSS 9.9) — binary · CVE-2025-49844. Status: Weaponized. Affects: Redis (embedded Lua scripting engine). Tags: redis, lua, use-after-free, uaf, memory-corruption, jop, jump-oriented-programming, shellcode, iced-x86, docker, cwe-416, rce.</description><category>binary</category><category>Critical</category><category>redis</category><category>lua</category><category>use-after-free</category><category>uaf</category><category>memory-corruption</category><category>jop</category><category>jump-oriented-programming</category><category>shellcode</category><category>iced-x86</category><category>docker</category><category>cwe-416</category><category>rce</category></item><item><title>Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-34299. Status: Weaponized. Affects: Monsta FTP (web-based FTP manager). Tags: monsta-ftp, rce, pre-auth, unrestricted-file-upload, cwe-434, php, ftp, docker, nuclei, kev.</description><category>network</category><category>Critical</category><category>monsta-ftp</category><category>rce</category><category>pre-auth</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>php</category><category>ftp</category><category>docker</category><category>nuclei</category><category>kev</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-41115. Status: PoC. Affects: Grafana Enterprise / Grafana Cloud, SCIM provisioning component (/api/scim/v2/Users). Tags: grafana, grafana-enterprise, scim, user-impersonation, privilege-escalation, id-collision, python, docker, cwe-287.</description><category>web</category><category>Critical</category><category>grafana</category><category>grafana-enterprise</category><category>scim</category><category>user-impersonation</category><category>privilege-escalation</category><category>id-collision</category><category>python</category><category>docker</category><category>cwe-287</category></item><item><title>OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</guid><description>High severity (CVSS 8.6) — cloud · CVE-2026-41900 (GHSA-8h25-q488-4hxw). Status: PoC. Affects: OpenLearnX code-execution/compiler service (Flask backend). Tags: docker, container-escape, rce, unauthenticated, code-execution-sandbox, info-disclosure, volume-mount, root.</description><category>cloud</category><category>High</category><category>docker</category><category>container-escape</category><category>rce</category><category>unauthenticated</category><category>code-execution-sandbox</category><category>info-disclosure</category><category>volume-mount</category><category>root</category></item><item><title>Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</guid><description>Medium severity — misc · CVE-2026-7482. Status: PoC. Affects: Ollama (GGUF model loader / quantization pipeline). Tags: ollama, gguf, heap-overflow, out-of-bounds-read, quantization, llm-serving, docker.</description><category>misc</category><category>Medium</category><category>ollama</category><category>gguf</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>quantization</category><category>llm-serving</category><category>docker</category></item><item><title>Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</guid><description>High severity — web · CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability). Status: PoC. Affects: A custom, deliberately vulnerabilized fork of Nginx 1.25.3's QUIC transport module (ngx_event_quic_transport.c), run inside a purpose-built Docker lab — not the stock upstream Nginx release. Tags: nginx, quic, http-3, heap-overflow, dos, fuzzing, dcid, academic-lab, docker.</description><category>web</category><category>High</category><category>nginx</category><category>quic</category><category>http-3</category><category>heap-overflow</category><category>dos</category><category>fuzzing</category><category>dcid</category><category>academic-lab</category><category>docker</category></item><item><title>MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0596-mlflow-mlserver-pickle-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0596-mlflow-mlserver-pickle-rce/</guid><description>Critical severity (CVSS 9.6) — web · CVE-2026-0596 (GHSA-rvhj-8chj-8v3c). Status: PoC. Affects: MLflow model serving stack (mlflow==2.11.1, mlserver==1.3.5, mlserver-mlflow==1.3.5). Tags: mlflow, mlserver, pickle, insecure-deserialization, rce, machine-learning, cwe-502, docker.</description><category>web</category><category>Critical</category><category>mlflow</category><category>mlserver</category><category>pickle</category><category>insecure-deserialization</category><category>rce</category><category>machine-learning</category><category>cwe-502</category><category>docker</category></item><item><title>MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34220-mikroorm-sql-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34220-mikroorm-sql-injection/</guid><description>High severity — web · CVE-2026-34220. Status: PoC. Affects: MikroORM (Node.js/TypeScript ORM). Tags: sql-injection, mikroorm, nodejs, typescript, orm, docker, database.</description><category>web</category><category>High</category><category>sql-injection</category><category>mikroorm</category><category>nodejs</category><category>typescript</category><category>orm</category><category>docker</category><category>database</category></item><item><title>LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</guid><description>Critical severity (CVSS 8.8) — web · CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29). Status: PoC. Affects: LiteLLM (open-source LLM proxy/gateway), POST /guardrails/test_custom_code endpoint. Tags: litellm, llm-proxy, sandbox-escape, bytecode-manipulation, cwe-913, docker, root-rce, authenticated.</description><category>web</category><category>Critical</category><category>litellm</category><category>llm-proxy</category><category>sandbox-escape</category><category>bytecode-manipulation</category><category>cwe-913</category><category>docker</category><category>root-rce</category><category>authenticated</category></item><item><title>Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54337-fireshare-file-overwrite/</guid><description>Info severity — web · CVE-2026-54337 (see [GHSA-hmh2-6g84-q8jx](https://github.com/ShaneIsrael/fireshare/security/advisories/GHSA-hmh2-6g84-q8jx)). Status: PoC. Affects: Fireshare (self-hosted video sharing app), &lt;= 1.16.3. Tags: fireshare, unauthenticated, arbitrary-file-write, argument-injection, ffmpeg, file-upload, cwe-73, docker.</description><category>web</category><category>Info</category><category>fireshare</category><category>unauthenticated</category><category>arbitrary-file-write</category><category>argument-injection</category><category>ffmpeg</category><category>file-upload</category><category>cwe-73</category><category>docker</category></item><item><title>Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34038-coolify-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34038-coolify-command-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-34038 (GHSA-qqrq-r9h4-x6wp). Status: PoC. Affects: Coolify (self-hosted PaaS/deployment platform). Tags: coolify, command-injection, cwe-78, rce, deployment, docker, api.</description><category>web</category><category>Critical</category><category>coolify</category><category>command-injection</category><category>cwe-78</category><category>rce</category><category>deployment</category><category>docker</category><category>api</category></item><item><title>Gitea act_runner container.options Host Namespace Escape</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_gitea-act-runner-container-options-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_gitea-act-runner-container-options-escape/</guid><description>High severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Gitea Actions act_runner (Docker-backed). Tags: gitea, act-runner, ci-cd, docker, container-escape, host-namespace, privilege-escalation, capabilities.</description><category>cloud</category><category>High</category><category>gitea</category><category>act-runner</category><category>ci-cd</category><category>docker</category><category>container-escape</category><category>host-namespace</category><category>privilege-escalation</category><category>capabilities</category></item><item><title>Docker cp Copy-Out Destination Escape via Symlink Race</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</guid><description>Medium severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Docker Engine / CLI. Tags: docker, container-escape, toctou, symlink-race, docker-cp, path-traversal, archive-extraction, host-file-write.</description><category>cloud</category><category>Medium</category><category>docker</category><category>container-escape</category><category>toctou</category><category>symlink-race</category><category>docker-cp</category><category>path-traversal</category><category>archive-extraction</category><category>host-file-write</category></item></channel></rss>