CVE-2025-13743

Severity CVSS v4.0:
LOW
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
09/12/2025
Last modified:
30/01/2026

Description

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:docker:docker_desktop:*:*:*:*:*:*:*:* 4.51.0 (including) 4.54.0 (excluding)