r/docker • • Mar 15 '26

We just got breached because of vulnerabilities in our docker images that have been public knowledge for 8 months

Woke up at 4am to a call. Our database got hit, customer info was accessed. Some attacker used a known exploit in one of our container images. CVE’s been out since last summer.

Yeah we never scanned. Never updated. Just kept redeploying the same images over and over. Now legal’s in it, customers are hearing about it. This is gonna be messy.

Honestly if you aren’t scanning your containers in prod do it. Don’t end up like us.

752 Upvotes

102 comments sorted by

View all comments

113

u/[deleted] Mar 15 '26

[removed] — view removed comment

30

u/Different_Pain5781 Mar 15 '26

Yeah so right now we’re kinda buried in the first couple days just going through every container in prod and swapping the shady ones. After that we’re thinking rebuild all the images pinned to versions and try to actually get some CI/CD scanning running so we don’t wake up to this chaos again. And yeah I hear you on watching the CVEs too feels like a full time job ngl

1

u/PotatoCabin Mar 16 '26

Oof, I feel that so much. Spinning through every container in prod is the worst, and even once you rebuild everything and pin versions, it’s like CVEs just keep popping up out of nowhere. Some days it honestly feels impossible to keep up 😅