Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

moby — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in moby, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the Moby project, an open-source platform for building, shipping, and running distributed systems. The content aggregates security issues spanning from the project's inception through current releases, ensuring comprehensive coverage of historical and recent flaws. Visitors can utilize this resource to track vendor advisories related to Docker and container runtime components, understand the technical details of specific weakness classes such as privilege escalation or information disclosure, and look up a product's vulnerability history to assess long-term security trends. By centralizing data from various sources including CVE databases and official project announcements, the page provides a unified view of the security landscape for Moby-based environments. This approach helps developers and security professionals identify recurring patterns in code defects and evaluate the impact of patches over time. The information is structured to facilitate quick reference and deep analysis, allowing users to correlate specific vulnerabilities with their underlying causes and affected versions. Whether auditing legacy deployments or securing new infrastructure, this resource serves as a foundational reference for understanding the security posture of the Moby ecosystem without requiring external searches or fragmented data collection.

Vendor: moby

CVE IDTitleCVSSSeverityPublished
CVE-2026-42306 Moby: Race condition in docker cp allows bind mount redirection to host path CWE-61 7.2 High2026-06-12
CVE-2026-41568 Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap CWE-81 6.1 Medium2026-06-12
CVE-2026-33997 Moby: Off-by-one error in plugin privilege validation CWE-193 6.8 Medium2026-03-31
CVE-2026-34040 Moby: AuthZ plugin bypass with oversized request body CWE-288 8.8 High2026-03-31
CVE-2025-54410 Moby's Firewalld reload removes bridge network isolation CWE-909 3.3 Low2025-07-30
CVE-2025-54388 Moby's Firewalld reload makes published container ports accessible from remote hosts CWE-909--2025-07-30
CVE-2024-41110 Moby authz zero length regression CWE-187 10.0 Critical2024-07-24
CVE-2024-32473 Moby IPv6 enabled on IPv4-only network interfaces CWE-668 4.7 Medium2024-04-18
CVE-2024-29018 External DNS requests from 'internal' networks could lead to data exfiltration CWE-669 5.9 Medium2024-03-20
CVE-2024-24557 Moby classic builder cache poisoning CWE-346 6.9 Medium2024-02-01
CVE-2023-28840 moby/moby's dockerd daemon encrypted overlay network may be unauthenticated CWE-420 7.5 High2023-04-04
CVE-2023-28841 moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted CWE-311 6.8 Medium2023-04-04
CVE-2023-28842 moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated CWE-420 6.8 Medium2023-04-04
CVE-2022-36109 Moby vulnerability relating to supplementary group permissions CWE-863 5.3 Medium2022-09-09
CVE-2022-24769 Default inheritable capabilities for linux container should be empty CWE-732 5.9 Medium2022-03-24
CVE-2021-41089 `docker cp` allows unexpected chmod of host files CWE-281 2.8 Low2021-10-04
CVE-2021-41091 Insufficiently restricted permissions on data directory in Docker Engine CWE-281 6.3 Medium2021-10-04
CVE-2021-21284 privilege escalation in Moby CWE-22 6.8 Medium2021-02-02
CVE-2021-21285 Docker daemon crash during image pull of malicious image CWE-400 6.5 Medium2021-02-02

All 19 known CVE vulnerabilities affecting moby with full Chinese analysis, references, and POCs where available.