Catalog / Moby

Moby security advisories

All 24 advisories Moby has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
2421 carry a CVE
critical
1
high
5
medium
12
low
6
Fix in the archive
7of 24 matched to a release
Oldest
2 Feb 20215.6 years ago

17 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-41568medium

Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

GHSA-vp62-88p7-qqf5Fixed in 29.5.1
CVE-2024-41110critical

Authz zero length regression

GHSA-v23v-6jw2-98fqFixed in 23.0.14, not held here
CVE-2024-32473medium

IPv6 enabled on IPv4-only network interfaces

GHSA-x84c-p2g9-rqv9Fixed in 26.0.2, not held here
CVE-2024-29018medium

External DNS requests from 'internal' networks could lead to data exfiltration

GHSA-mq39-4gv4-mvpxFixed in 26.0.0, not held here
CVE-2024-24557medium

Classic builder cache poisoning

GHSA-xw73-rw38-6vjcFixed in 25.0.2, not held here
GHSA-jq35-85cj-fj4pmedium

/sys/devices/virtual/powercap accessible by default to containers

Fixed in 24.0.7, not held here
CVE-2023-28840high

Encrypted overlay network may be unauthenticated

GHSA-232p-vwff-86mpFixed in 23.0.3, not held here
CVE-2023-28841medium

Encrypted overlay network traffic may be unencrypted

GHSA-33pg-m6jh-5237Fixed in 23.0.3, not held here
CVE-2023-28842medium

Encrypted overlay network with a single endpoint is unauthenticated

GHSA-6wrf-mxfj-pf5pFixed in 23.0.3, not held here
GHSA-vwm3-crmr-xfxwhigh

The Swarm VXLAN port may be exposed to attack due to ambiguous documentation

GHSA-vp35-85q5-9f25low

Container build can leak any path on the host into the container (using Git CVE-2022-39253)

Fixed in 20.10.20, not held here
CVE-2022-36109low

Security vulnerability relating to supplementary group permissions

GHSA-rc4r-wh2q-q6c4Fixed in 20.10.18, not held here
CVE-2022-24769low

Default inheritable capabilities for linux container should be empty

GHSA-2mm7-x5h6-5pvqFixed in 20.10.14, not held here
CVE-2021-41190medium

Ambiguous OCI manifest parsing

GHSA-xmmx-7jpf-fx42Fixed in 20.10.11, not held here
CVE-2021-41089low

`docker cp` allows unexpected chmod of host files

GHSA-v994-f8vw-g7j4Fixed in 20.10.9, not held here
CVE-2021-41091medium

Insufficiently restricted permissions on data directory

GHSA-3fwx-pjgw-3558Fixed in 20.10.9, not held here
CVE-2021-21285medium

Docker daemon crash during image pull of malicious image

GHSA-6fj5-m822-rqx8Fixed in 19.03.15, not held here
CVE-2021-21284low

Access to remapped root allows privilege escalation to real root

GHSA-7452-xqpj-6rpcFixed in 19.03.15, not held here