vciy

CVEs we hold for Moby

Records whose assigning authority named Moby as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-75593BuildKit: Malicious client can bypass destination directory validation on local sources uploadmoby buildkit
CVE-2026-61712BuildKit: Possible runtime DoS via unbounded group parsingmoby buildkit
CVE-2026-61711BuildKit: Custom frontend could bypass Seccomp/AppArmormoby buildkit
CVE-2026-42306Moby: Race condition in docker cp allows bind mount redirection to host pathmoby
CVE-2026-41568Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swapmoby
CVE-2026-41567Docker: `PUT /containers/{id}/archive` executes container binary on the hostmoby/v2/daemon; moby Docker Engine; docker/daemon
CVE-2026-35469SpdyStream: DOS on CRImoby spdystream
CVE-2026-34040Moby: AuthZ plugin bypass with oversized request bodymoby
CVE-2026-33997Moby: Off-by-one error in plugin privilege validationmoby
CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted filesmoby buildkit
CVE-2026-33747BuildKit vulnerable to malicious frontend causing file escape outside of storage rootmoby buildkit
CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link followingmoby go-archive; Docker Sandboxes; Docker Desktop…
CVE-2026-15793Git source checkout from a bundle file could lead to command injectionmoby BuildKit
CVE-2026-15792Possible panic when incorrect parameters sent from frontendmoby BuildKit
CVE-2026-15791LLB file operation can be tricked to remove /tmp directory contentsmoby BuildKit
CVE-2026-15789Malicious client can bypass destination directory validation on local sources uploadmoby BuildKit
CVE-2026-15788WCOW cache mount source selector resolves NTFS junctions outside of cache rootmoby BuildKit
CVE-2025-54410Moby's Firewalld reload removes bridge network isolationmoby
CVE-2025-54388Moby's Firewalld reload makes published container ports accessible from remote hostsmoby
CVE-2024-41110Moby authz zero length regressionmoby
CVE-2024-32473Moby IPv6 enabled on IPv4-only network interfacesmoby
CVE-2024-29018External DNS requests from 'internal' networks could lead to data exfiltrationmoby
CVE-2024-24557Moby classic builder cache poisoningmoby
CVE-2024-23653BuildKit interactive containers API does not validate entitlements checkmoby buildkit
CVE-2024-23652BuildKit possible host system access from mount stub cleanermoby buildkit
CVE-2024-23651BuildKit possible race condition with accessing subpaths from cache mountsmoby buildkit
CVE-2024-23650BuildKit possible panic when incorrect parameters sent from frontendmoby buildkit
CVE-2023-28842moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmoby
CVE-2023-28841moby/moby's dockerd daemon encrypted overlay network traffic may be unencryptedmoby
CVE-2023-28840moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmoby
CVE-2023-26054Credentials inlined to Git URLs could end up in provenance attestation in BuildKitmoby buildkit
CVE-2022-36109Moby vulnerability relating to supplementary group permissionsmoby
CVE-2022-24769Default inheritable capabilities for linux container should be emptymoby
CVE-2021-41091Insufficiently restricted permissions on data directory in Docker Enginemoby
CVE-2021-41089`docker cp` allows unexpected chmod of host filesmoby
CVE-2021-32847Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmoby hyperkit
CVE-2021-32846Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmoby hyperkit
CVE-2021-32845Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notifymoby hyperkit
CVE-2021-32844no title heldmoby hyperkit
CVE-2021-32843no title heldmoby hyperkit
CVE-2021-21285Docker daemon crash during image pull of malicious imagemoby
CVE-2021-21284privilege escalation in Mobymoby

42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.