Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

moby — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting moby. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Moby serves as the foundational open-source framework for containerization, primarily powering Docker and enabling the creation, deployment, and running of distributed applications. Its architecture facilitates lightweight virtualization but has historically exposed specific vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws within its daemon and API interfaces. With thirty CVEs currently on record, these issues often stem from improper input validation, insecure default configurations, or race conditions in the container runtime. Notable incidents have highlighted risks related to container breakout attacks, where compromised containers gain access to the host system, potentially leading to full infrastructure compromise. Security assessments emphasize the critical need for regular patching, strict access controls, and continuous monitoring of the Moby engine to mitigate these persistent threats in modern cloud-native environments.

CVE ID Title CVSS Severity Published
CVE-2026-75593 BuildKit: Malicious client can bypass destination directory validation on local sources upload — buildkit CWE-22 7.2 High 2026-08-19
CVE-2026-61711 BuildKit: Custom frontend could bypass Seccomp/AppArmor — buildkit CWE-20 5.3 Medium 2026-08-19
CVE-2026-61712 BuildKit: Possible runtime DoS via unbounded group parsing — buildkit CWE-770 2.3 Low 2026-08-19
CVE-2026-17106 Tar extraction in moby/go-archive can write outside the destination directory via link following — go-archive CWE-59 7.1 High 2026-08-18
CVE-2026-15793 Git source checkout from a bundle file could lead to command injection — BuildKit CWE-88 - - 2026-07-21
CVE-2026-15791 LLB file operation can be tricked to remove /tmp directory contents — BuildKit CWE-22 - - 2026-07-21
CVE-2026-15792 Possible panic when incorrect parameters sent from frontend — BuildKit CWE-20 - - 2026-07-21
CVE-2026-15789 Malicious client can bypass destination directory validation on local sources upload — BuildKit CWE-22 - - 2026-07-21
CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root — BuildKit CWE-59 - - 2026-07-20
CVE-2026-42306 Moby: Race condition in docker cp allows bind mount redirection to host path — moby CWE-61 7.2 High 2026-06-12
CVE-2026-41568 Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap — moby CWE-81 6.1 Medium 2026-06-12
CVE-2026-41567 Docker: `PUT /containers/{id}/archive` executes container binary on the host — moby/v2/daemon CWE-427 7.2 High 2026-06-05
CVE-2026-35469 SpdyStream: DOS on CRI — spdystream CWE-770 8.7 High 2026-04-16
CVE-2026-33997 Moby: Off-by-one error in plugin privilege validation — moby CWE-193 6.8 Medium 2026-03-31
CVE-2026-34040 Moby: AuthZ plugin bypass with oversized request body — moby CWE-288 8.8 High 2026-03-31
CVE-2026-33748 BuildKit Git URL subdir component can cause access to restricted files — buildkit CWE-22 7.5 - 2026-03-27
CVE-2026-33747 BuildKit vulnerable to malicious frontend causing file escape outside of storage root — buildkit CWE-22 8.4 High 2026-03-27
CVE-2025-54410 Moby's Firewalld reload removes bridge network isolation — moby CWE-909 3.3 Low 2025-07-30
CVE-2025-54388 Moby's Firewalld reload makes published container ports accessible from remote hosts — moby CWE-909 - - 2025-07-30
CVE-2024-41110 Moby authz zero length regression — moby CWE-187 10.0 Critical 2024-07-24
CVE-2024-32473 Moby IPv6 enabled on IPv4-only network interfaces — moby CWE-668 4.7 Medium 2024-04-18
CVE-2024-29018 External DNS requests from 'internal' networks could lead to data exfiltration — moby CWE-669 5.9 Medium 2024-03-20
CVE-2024-24557 Moby classic builder cache poisoning — moby CWE-346 6.9 Medium 2024-02-01
CVE-2024-23653 BuildKit interactive containers API does not validate entitlements check — buildkit CWE-863 9.8 Critical 2024-01-31
CVE-2024-23652 BuildKit possible host system access from mount stub cleaner — buildkit CWE-22 10.0 Critical 2024-01-31
CVE-2024-23651 BuildKit possible race condition with accessing subpaths from cache mounts — buildkit CWE-362 8.7 High 2024-01-31
CVE-2024-23650 BuildKit possible panic when incorrect parameters sent from frontend — buildkit CWE-754 5.3 Medium 2024-01-31
CVE-2023-28840 moby/moby's dockerd daemon encrypted overlay network may be unauthenticated — moby CWE-420 7.5 High 2023-04-04
CVE-2023-28841 moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted — moby CWE-311 6.8 Medium 2023-04-04
CVE-2023-28842 moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated — moby CWE-420 6.8 Medium 2023-04-04

This page lists every published CVE security advisory associated with moby. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.