Data leak due to Docker Hub images

watch 1m, 12s
views 2

14:15, 12.12.2025

After a security investigation by Flare, it became known that 10,456 Docker Hub container images provide access to protected data. The data relates to LLM model keys, CI/CD databases, and production systems.

Details about the data leak

The leak affected large Fortune 500 companies and even a national bank.

Docker Hub is considered to be the most popular container registry, where ready-made images are uploaded and distributed. Most often, developers use Docker images to deploy software and optimise the entire development cycle. However, incorrect image creation can directly lead to the disclosure of secrets.

After thoroughly checking the container images, it became clear that the most common secrets were access tokens to AI models from Anthropic, OpenAI, Groq, and Gemini. In total, there were 4,000 keys, and almost 42 percent of the scanned images contained 5 confidential values.

Data leaks can lead to critical risks. During the audit, 100 companies were identified, most of which operate in the software and AI sectors. Additionally, more than 10 companies in the banking and financial sectors experienced confidential data leaks.

The most common mistake was the use of .ENV files, which are needed to store credentials, project tokens, and cloud access keys. Encoded API tokens for AI were also found in YAML, Python, config.json, and GitHub tokens.

Flare recommends avoiding storing secrets in container images and instead centralising management with a manager and dedicated storage. Companies should also use active scanning throughout the software development lifecycle while simultaneously revoking old sessions.

Share

Was this article helpful to you?

VPS popular offers

-8.8%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
400 GB HDD
Bandwidth
Bandwidth
300 Gb
wKVM-HDD HK 16384 Windows

45.33 /mo

/mo

Billed annually

-20.5%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
8 TB
KVM-SSD 8192 Metered Linux

57 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
200 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 8192 Linux

25.25 /mo

/mo

Billed annually

-12.8%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
1 TB
wKVM-SSD 1024 Metered Windows

17 /mo

/mo

Billed annually

-16.3%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
40 Mbps
DDoS Protected SSD-KVM 2048 Linux

48 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Epyc Cores
RAM
RAM
16 GB
Space
Space
150 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 16384
OS
CentOS
Software
Software
Keitaro

55.54 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
Unlimited
10Ge-KVM-SSD 2048 Linux

30.3 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Epyc Cores
RAM
RAM
8 GB
Space
Space
100 GB NVMe
Bandwidth
Bandwidth
Unlimited
wKVM-NVMe 8192 Windows

28.99 /mo

/mo

Billed annually

-29.4%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
2 TB
KVM-SSD 2048 Metered Linux

17 /mo

/mo

Billed annually

-15%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
80 Mbps
DDoS Protected SSD-wKVM 8192 Windows

101 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.