A race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
CVE-2026-41568 is a MEDIUM severity vulnerability in Moby Docker Engine and Daemon. A race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.
CVE-2026-41567 is a high-severity vulnerability in the Moby container framework. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue affects versions prior to 29.5.1 and in moby/mo [truncated]
CVE-2026-34040 is a high-severity security vulnerability in Moby, an open-source container framework. The vulnerability, which has a CVSS score of 8.8, allows attackers to bypass authorization plugins (AuthZ). This issue was patched in version 29.3.1 of Moby.
CVE-2026-33997 is a security vulnerability in Moby, an open-source container framework. Prior to version 29.3.1, the vulnerability allows plugins privilege validation to be bypassed during Docker plugin installation. The issue arises from an error in the daemon's privilege comparison logic, which may incorrectly accept a privilege set that differs from the one approved by the user. This affects plugins th [truncated]