Cybersecurity — 2026-04-08
Critical Docker Engine Flaw Allows Authorization Bypass and Host Takeover
A high-severity Docker Engine vulnerability (CVE-2026-34040, CVSS 8.8) stems from an incomplete fix for a prior maximum-severity flaw. When API requests exceed 1 MB, Docker's middleware silently truncates the request body before forwarding to
2 sources
- Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access -
The Hacker News - Docker Vulnerability Let Attackers Bypass authorization and Gain Host Access -
Cybersecurity News