7.5highHigh
CVE-2026-64773
Apple Container
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.
Exploitation status
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is reachable over a network, without needing local access.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, no action by a user is required.
Scoring
- CVSS
- 7.5 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H- Weakness
- CWE-770
- Assigned by
- product-security@apple.com
Dates
- Published
- 2026-08-20
- Last modified
- 2026-09-01
- Sources
- NVD
Affected products
- Apple Container0.3.0 - 1.2.0
As listed in the NVD configuration data. Not a statement about your estate.