Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/docker/docker
  4. ›
  5. CVE-2025-54388

CVE-2025-54388: Moby firewalld reload makes published container ports accessible from remote hosts

July 29, 2025 (updated September 10, 2025)

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby is commonly referred to as Docker, or Docker Engine.

Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.

References

  • github.com/advisories/GHSA-x4rx-4gw3-53p4
  • github.com/moby/moby
  • github.com/moby/moby/commit/bea959c7b793b32a893820b97c4eadc7c87fabb0
  • github.com/moby/moby/pull/50506
  • github.com/moby/moby/security/advisories/GHSA-x4rx-4gw3-53p4
  • nvd.nist.gov/vuln/detail/CVE-2025-54388

Code Behaviors & Features

Detect and mitigate CVE-2025-54388 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 28.2.0 before 28.3.3

Fixed versions

  • 28.3.3

Solution

Upgrade to version 28.3.3 or above.

Impact 4.6 MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-909: Missing Initialization of Resource

Source file

go/github.com/docker/docker/CVE-2025-54388.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 09 Dec 2025 00:18:20 +0000.