Data leak due to Docker Hub images

watch 1m, 12s
views 2

14:15, 12.12.2025

After a security investigation by Flare, it became known that 10,456 Docker Hub container images provide access to protected data. The data relates to LLM model keys, CI/CD databases, and production systems.

Details about the data leak

The leak affected large Fortune 500 companies and even a national bank.

Docker Hub is considered to be the most popular container registry, where ready-made images are uploaded and distributed. Most often, developers use Docker images to deploy software and optimise the entire development cycle. However, incorrect image creation can directly lead to the disclosure of secrets.

After thoroughly checking the container images, it became clear that the most common secrets were access tokens to AI models from Anthropic, OpenAI, Groq, and Gemini. In total, there were 4,000 keys, and almost 42 percent of the scanned images contained 5 confidential values.

Data leaks can lead to critical risks. During the audit, 100 companies were identified, most of which operate in the software and AI sectors. Additionally, more than 10 companies in the banking and financial sectors experienced confidential data leaks.

The most common mistake was the use of .ENV files, which are needed to store credentials, project tokens, and cloud access keys. Encoded API tokens for AI were also found in YAML, Python, config.json, and GitHub tokens.

Flare recommends avoiding storing secrets in container images and instead centralising management with a manager and dedicated storage. Companies should also use active scanning throughout the software development lifecycle while simultaneously revoking old sessions.

Share

Was this article helpful to you?

VPS popular offers

-10%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
20 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 1024 Linux

6.6 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 2048 Linux

8.3 /mo

/mo

Billed annually

-5%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
40 GB HDD
Bandwidth
Bandwidth
Unlimited
wKVM-HDD 1024 Windows

12.1 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Epyc Cores
RAM
RAM
4 GB
Space
Space
50 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 4096
OS
CentOS
Software
Software
Keitaro

18.1 /mo

/mo

Billed annually

-15.4%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
150 GB SSD
Bandwidth
Bandwidth
100 Mbps
DDoS Protected SSD-wKVM 16384 Windows

130 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB HDD
Bandwidth
Bandwidth
300 Gb
KVM-HDD HK 4096 Linux

12.24 /mo

/mo

Billed annually

-10%

CPU
CPU
2 Xeon Cores
RAM
RAM
512 MB
Space
Space
10 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 512 Linux

5.2 /mo

/mo

Billed annually

-10%

CPU
CPU
6 Xeon Cores
RAM
RAM
16 GB
Space
Space
150 GB SSD
Bandwidth
Bandwidth
Unlimited
KVM-SSD 16384 Linux

49.99 /mo

/mo

Billed annually

-20.4%

CPU
CPU
2 Xeon Cores
RAM
RAM
2 GB
Space
Space
30 GB SSD
Bandwidth
Bandwidth
300 GB
KVM-SSD 2048 HK Linux

18 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
Unlimited
10Ge-KVM-SSD 4096 Linux

60.5 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.