logo

Whispers of XZ Utils Backdoor Live on in Old Docker Images

ID: 0ab36c96-2290-5c97-8b7f-981110299733

STIX ID: report--0ab36c96-2290-5c97-8b7f-981110299733

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-13

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Researchers report that the high-severity XZ Utils backdoor (CVE-2024-3094) — previously removed after disclosure — persists in a number of Debian-based Docker Hub images; Binarly identified 35 affected images (12 direct, 23 second-order). While maintainers and registries mitigated widespread impact and exploitability is limited by several unlikely conditions (old tags, running a system and SSH inside the container), the presence of backdoored builds in public registries poses a lasting supply-chain risk and demonstrates how short-lived compromises can persist in container ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.