Advisory Details

March 3rd, 2026

Docker Desktop for Mac Docker Model Runner Exposed Dangerous Function Denial-of-Service Vulnerability

ZDI-26-150
ZDI-CAN-28379

CVE ID CVE-2026-28400
CVSS SCORE 7.3, AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
AFFECTED VENDORS Docker
AFFECTED PRODUCTS Desktop
VULNERABILITY DETAILS

This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Docker Desktop. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.

The specific flaw exists within Docker Model Runner. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.

ADDITIONAL DETAILS Docker has issued an update to correct this vulnerability. More details can be found at:
https://github.com/docker/model-runner/security/advisories/GHSA-m456-c56c-hh5c#advisory-comment-165261
DISCLOSURE TIMELINE
  • 2025-11-05 - Vulnerability reported to vendor
  • 2026-03-03 - Coordinated public release of advisory
  • 2026-03-03 - Advisory Updated
CREDIT Nitesh Surana (niteshsurana.com) of Trend Research
BACK TO ADVISORIES