GHSA-x4rx-4gw3-53p4 · Severity: medium · Ecosystem: go — Moby firewalld reload makes published container ports accessible from remote hosts
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when the firewalld service is reloaded it removes all iptables rules including those created by Docker. While Docker should automatically recreate these rules, versions before 28.3.3 fail to recreate the specific rules that block external access to containers. This means that after a firewalld reload, containers with ports published to localhost (like 127.0.0.1:8080) become accessible from remote machines that have network routing to the Docker bridge, even though they should only be accessible from the host itself. The vulnerability only affects explicitly published ports - unpublished ports remain protected. This issue is fixed in version 28.3.3.
Conclusion & alert: CVE-2025-54388 is rated Low Risk (20.5/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-07-31 | — | 0.01% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.1 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.6 | 3.1 | MEDIUM |
|
2.1 | 2.5 | [email protected] |
GHSA-x4rx-4gw3-53p4 · Severity: medium · Ecosystem: go — Moby firewalld reload makes published container ports accessible from remote hosts
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-54388: 1 source package rows (docker); 2 state rows across 2 repos (3.22-community, edge-community); fixed 2, open 0. | https://security.alpinelinux.org/vuln/CVE-2025-54388 |
debian
|
unimportant | CVE-2025-54388 unimportant priority: Debian including 1 source packages (docker.io), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-54388 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-54388 |
suse
|
medium | CVE-2025-54388 severity moderate: SUSE including 268 source package names (2.2.0-4.52:pam-1.6.1-slfo.1.1_3.1, 2.2.0-4.53:pam-1.6.1-slfo.1.1_3.1, …), 610 product×package rows across 256 product lines (Container suse/sl-micro/6.0/base-os-container, Container suse/sl-micro/6.0/toolbox, … (256 product lines)): Fixed 361, Known Affected 231, Known Not Affected 12, First Fixed 6. | https://www.suse.com/security/cve/CVE-2025-54388/ |
ubuntu
|
medium | CVE-2025-54388 medium priority: Ubuntu including 2 source packages (docker.io, docker.io-app), 14 status rows across 8 suites (bionic, focal, jammy, noble, plucky, questing, upstream, xenial): needs-triage 7, needed 3, ignored 2, not-affected 1, released 1. | https://ubuntu.com/security/CVE-2025-54388 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| mobyproject | moby | >= 28.2.0, < 28.3.3 | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/moby/moby/commit/bea959c7b793b32a893820b97c4eadc7c87fabb0 | Patch |
| https://github.com/moby/moby/pull/50506 | Issue Tracking Patch |
| https://github.com/moby/moby/security/advisories/GHSA-x4rx-4gw3-53p4 | Vendor Advisory |