High severity7.5NVD Advisory· Published Aug 20, 2026· Updated Sep 1, 2026
CVE-2026-64773
CVE-2026-64773
Description
An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=1.2.0
Patches
Vulnerability mechanics
References
1- github.com/apple/container/security/advisories/GHSA-wg28-286f-56v6nvdPatchVendor AdvisoryMitigation
News mentions
1- Apple Patches Six Vulnerabilities in macOS, watchOS, and Container TechVypr Intelligence · Aug 21, 2026