Back to Database
Status published
Low
CVE-2025-13743
Expired Personal Access Tokens (PATs) are recorded in Docker Desktop diagnostic logs
Vulnerability Description
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13743
Credits & Attribution
No credits recorded in the NVD database.
More from Docker
View All →CVE-2025-9164
Multiple DLL Search Order Hijacking Vulnerabilities in Docker Desktop Installer for Windows
High
8.8
CVE-2025-9074
Docker Desktop allows unauthenticated access to Docker Engine API from containers
Critical
9.3
CVE-2025-6587
Exposure of system environment variables in Docker Desktop diagnostic logs
Medium
5.2
CVE-2025-4095
Registry Access Management (RAM) policies not applied when sign-in enforcement is configured via a configuration profile
Medium
4.3
CVE-2025-3911
Exposure in Docker Desktop logs of environment variables configured for running containers
Medium
5.2
Affected Vendor
Docker
View all reports →Affected Software
Docker Desktop
Vulnerable Versions:
4.51.0
Timeline
Official Publish:
December 9th, 2025
Last Modified:
December 10th, 2025
Added to House:
July 22nd, 2026