Vulnerabilities in Moby
54 resultsCVE-2026-41567HIGHDocker: `PUT /containers/{id}/archive` executes container binary on the hostEPSS 0.2%CVE-2026-34040HIGHMoby: AuthZ plugin bypass with oversized request bodyEPSS 0.2%CVE-2026-93317MEDIUMContainer blob cache can accept unverified contentEPSS 0.2%CVE-2025-54410LOWMoby's Firewalld reload removes bridge network isolationEPSS 0.2%CVE-2026-93321MEDIUMMalformed LLB file operation can crash buildkitdEPSS 0.2%CVE-2026-93322MEDIUMMalformed MergeOp can crash the BuildKit daemonEPSS 0.1%CVE-2026-93320MEDIUMBuildKit improperly handles special files in build snapshotsEPSS 0.1%CVE-2026-93323MEDIUMOversized Dockerfile or .dockerignore can exhaust buildkitd memoryEPSS 0.1%CVE-2026-42306HIGHMoby: Race condition in docker cp allows bind mount redirection to host pathEPSS 0.1%CVE-2026-41568MEDIUMMoby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swapEPSS 0.1%CVE-2026-93315MEDIUMBuildKit proxy CA cleanup can be disrupted by build stepsEPSS 0.1%CVE-2026-93319MEDIUMA malicious frontend can cause a daemon panicEPSS 0.1%CVE-2026-92543HIGHDocker Engine insecure-registry fallback via malicious DNS responsesEPSS —CVE-2026-92542MEDIUMBlind VXLAN injection into encrypted overlay networks from cluster peerEPSS —