CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects Docker.
CVE
CVE-2026-7309
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
Docker
Original NVD Description
A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulnerability allows for information disclosure, specifically impacting the confidentiality of build traffic.
Related CVEs
Other vulnerabilities affecting the same vendor(s)