Summary
The published repository security advisory GHSA-c7vj-4cqh-8cv9 for wollomatic/socket-proxy is not currently available through the global
GitHub Advisory Database.
The advisory is published in the source repository:
However, the corresponding global advisory URL returns HTTP 404:
Advisory details
- GHSA:
GHSA-c7vj-4cqh-8cv9
- Repository:
wollomatic/socket-proxy
- Package:
github.com/wollomatic/socket-proxy
- Ecosystem: Go
- Severity: Critical
- CVSS:
9.6
- Affected versions:
>= 1.8.0, <= 1.12.3
- Patched version:
1.13.0
- Published: 2026-08-13
- CVE: No known CVE
The repository advisory describes a restriction bypass in the -allowbindmountfrom / SP_ALLOWBINDMOUNTFROM control. Under affected
configurations, a client may be able to create Docker containers, Swarm services, or volumes with host bind mounts outside the configured
allowlist.
Request
Could you please review the advisory and either:
- ingest it into the global GitHub Advisory Database, or
- provide information about why it is not eligible for ingestion?
A CVE was already requested through GitHub's "Request CVE" workflow some time ago. However, no CVE has been assigned so far, and the advisory
is still not available through the global GitHub Advisory Database (see also wollomatic/socket-proxy#176).
Thank you.
Summary
The published repository security advisory
GHSA-c7vj-4cqh-8cv9forwollomatic/socket-proxyis not currently available through the globalGitHub Advisory Database.
The advisory is published in the source repository:
GHSA-c7vj-4cqh-8cv9
However, the corresponding global advisory URL returns HTTP 404:
https://github.com/advisories/GHSA-c7vj-4cqh-8cv9
Advisory details
GHSA-c7vj-4cqh-8cv9wollomatic/socket-proxygithub.com/wollomatic/socket-proxy9.6>= 1.8.0, <= 1.12.31.13.0The repository advisory describes a restriction bypass in the
-allowbindmountfrom/SP_ALLOWBINDMOUNTFROMcontrol. Under affectedconfigurations, a client may be able to create Docker containers, Swarm services, or volumes with host bind mounts outside the configured
allowlist.
Request
Could you please review the advisory and either:
A CVE was already requested through GitHub's "Request CVE" workflow some time ago. However, no CVE has been assigned so far, and the advisory
is still not available through the global GitHub Advisory Database (see also wollomatic/socket-proxy#176).
Thank you.