From 2e07997f0ad208a2ddcec4d113057bf9148543b0 Mon Sep 17 00:00:00 2001 From: temenuzhka-thede <148288201+temenuzhka-thede@users.noreply.github.com> Date: Wed, 10 Dec 2025 12:20:17 -0600 Subject: [PATCH] Update security-announcements.md for CVE-2025-13743 (#23825) Update security notes to reference CVE-2025-13743 https://www.cve.org/CVERecord?id=CVE-2025-13743 ## Description ## Related issues or tickets ## Reviews - [ ] Technical review - [ ] Editorial review - [ ] Product review --- content/manuals/security/security-announcements.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/content/manuals/security/security-announcements.md b/content/manuals/security/security-announcements.md index f3a74bcdfb..572fcf1663 100644 --- a/content/manuals/security/security-announcements.md +++ b/content/manuals/security/security-announcements.md @@ -12,6 +12,12 @@ toc_max: 2 {{< rss-button feed="/security/security-announcements/index.xml" text="Subscribe to security RSS feed" >}} +## Docker Desktop 4.54.0 security update: CVE-2025-13743 + +A vulnerability in Docker Desktop was fixed on December 4 in the [4.54.0](/manuals/desktop/release-notes.md#4540) release: + +- Fixed [CVE-2025-13743](https://www.cve.org/cverecord?id=CVE-2025-13743) where Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. + ## Docker Desktop 4.49.0 security update: CVE-2025-9164 A vulnerability in Docker Desktop for Windows was fixed on October 23 in the [4.49.0](/manuals/desktop/release-notes.md#4490) release: