PatchSiren

Moby CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Moby CVE published 2026-06-05

CVE-2026-41567

CVE-2026-41567 is a high-severity vulnerability in the Moby container framework. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue affects versions prior to 29.5.1 and in moby/mo [truncated]