PatchSiren

moby CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW moby CVE published 2026-08-19

CVE-2026-61712

BuildKit is vulnerable to a denial-of-service attack due to reading attacker-controlled /etc/passwd and /etc/group files without an upper bound, potentially leading to out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. Affected users should review their current BuildKit version and take steps to update it. The vulnerability could be exploited by a malicious base ima [truncated]

MEDIUM moby CVE published 2026-08-19

CVE-2026-61711

CVE-2026-61711 is a vulnerability in BuildKit, a toolkit for converting source code to build artifacts. A custom frontend could place an invalid SecurityMode value in a crafted build request, which could lead to disabled Seccomp and AppArmor protections for the build container. This issue is fixed in version 0.31.1. The vulnerability allows an attacker to potentially exploit the build container with reduc [truncated]

HIGH moby CVE published 2026-06-12

CVE-2026-42306

A race condition during docker cp mount setup allows a malicious container to redirect a bind mount target to an arbitrary host path, potentially overwriting host files or causing denial of service. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

MEDIUM moby CVE published 2026-06-12

CVE-2026-41568

CVE-2026-41568 is a MEDIUM severity vulnerability in Moby Docker Engine and Daemon. A race condition during docker cp mount setup allows a malicious container to create empty files or directories at arbitrary absolute paths on the host filesystem. This issue has been patched in Docker Engine version 29.5.1 and Moby Daemon version 2.0.0-beta.14.

HIGH Moby CVE published 2026-06-05

CVE-2026-41567

A malicious container image can achieve arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container. This vulnerability affects Moby installations prior to Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. The issue allows for potential host root UID and unrestricted capabilities exploitation if a user uploads a compressed archive into a container cre [truncated]

HIGH moby CVE published 2026-03-31

CVE-2026-34040

CVE-2026-34040 is a high-severity security vulnerability in Moby, an open-source container framework. The vulnerability, which has a CVSS score of 8.8, allows attackers to bypass authorization plugins (AuthZ). This issue was patched in version 29.3.1 of Moby.

MEDIUM moby CVE published 2026-03-31

CVE-2026-33997

A security vulnerability was detected in Moby, an open-source container framework, that allows plugins' privilege validation to be bypassed during Docker plugin installation. The vulnerability is caused by an error in the daemon's privilege comparison logic, which may incorrectly accept a privilege set that differs from the one approved by the user. Plugins requesting exactly one privilege are also affect [truncated]