Docker CVE-2026-34040 enables AuthZ bypass via padded requests, risking host compromise; fixed in version 29.3.1.
A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.