Data leak due to Docker Hub images

watch 1m, 12s
views 2

14:15, 12.12.2025

After a security investigation by Flare, it became known that 10,456 Docker Hub container images provide access to protected data. The data relates to LLM model keys, CI/CD databases, and production systems.

Details about the data leak

The leak affected large Fortune 500 companies and even a national bank.

Docker Hub is considered to be the most popular container registry, where ready-made images are uploaded and distributed. Most often, developers use Docker images to deploy software and optimise the entire development cycle. However, incorrect image creation can directly lead to the disclosure of secrets.

After thoroughly checking the container images, it became clear that the most common secrets were access tokens to AI models from Anthropic, OpenAI, Groq, and Gemini. In total, there were 4,000 keys, and almost 42 percent of the scanned images contained 5 confidential values.

Data leaks can lead to critical risks. During the audit, 100 companies were identified, most of which operate in the software and AI sectors. Additionally, more than 10 companies in the banking and financial sectors experienced confidential data leaks.

The most common mistake was the use of .ENV files, which are needed to store credentials, project tokens, and cloud access keys. Encoded API tokens for AI were also found in YAML, Python, config.json, and GitHub tokens.

Flare recommends avoiding storing secrets in container images and instead centralising management with a manager and dedicated storage. Companies should also use active scanning throughout the software development lifecycle while simultaneously revoking old sessions.

Share

Was this article helpful to you?

VPS popular offers

-10%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
40 GB HDD
Bandwidth
Bandwidth
Unlimited
KVM-HDD 1024 Linux

6.1 /mo

/mo

Billed annually

-12.8%

CPU
CPU
3 Xeon Cores
RAM
RAM
1 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
1 TB
wKVM-SSD 1024 Metered Windows

17 /mo

/mo

Billed annually

-15.4%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
60 Mbps
DDoS Protected SSD-wKVM 4096 Windows

73 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Epyc Cores
RAM
RAM
4 GB
Space
Space
50 GB NVMe
Bandwidth
Bandwidth
Unlimited
Keitaro KVM 4096
OS
CentOS
Software
Software
Keitaro

18.1 /mo

/mo

Billed annually

-10%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
MT5 KVM 4096 Windows

19.99 /mo

/mo

Billed annually

-9.2%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
Unlimited
10Ge-wKVM-SSD 4096 Windows

72 /mo

/mo

Billed annually

-21.4%

CPU
CPU
6 Xeon Cores
RAM
RAM
8 GB
Space
Space
100 GB SSD
Bandwidth
Bandwidth
500 GB
wKVM-SSD 8192 HK Windows

67 /mo

/mo

Billed annually

-20.6%

CPU
CPU
6 Xeon Cores
RAM
RAM
8GB
Space
Space
100GB SSD
Bandwidth
Bandwidth
500GB
KVM-SSD 8192 HK Linux

59 /mo

/mo

Billed annually

-9.6%

CPU
CPU
8 Xeon Cores
RAM
RAM
32 GB
Space
Space
200 GB SSD
Bandwidth
Bandwidth
12 TB
wKVM-SSD 32768 Metered Windows

156 /mo

/mo

Billed annually

-16.2%

CPU
CPU
4 Xeon Cores
RAM
RAM
4 GB
Space
Space
50 GB SSD
Bandwidth
Bandwidth
60 Mbps
DDoS Protected SSD-KVM 4096 Linux

67 /mo

/mo

Billed annually

Other articles on this topic

cookie

Accept cookies & privacy policy?

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the HostZealot website.