CVE-2026-34040Moby: AuthZ plugin bypass with oversized request bodymoby
CVE-2026-33997Moby: Off-by-one error in plugin privilege validationmoby
CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted filesmoby buildkit
CVE-2026-33747BuildKit vulnerable to malicious frontend causing file escape outside of storage rootmoby buildkit
CVE-2026-17106Tar extraction in moby/go-archive can write outside the destination directory via link followingmoby go-archive; Docker Sandboxes; Docker Desktop…
CVE-2026-15793Git source checkout from a bundle file could lead to command injectionmoby BuildKit
CVE-2026-15792Possible panic when incorrect parameters sent from frontendmoby BuildKit
CVE-2026-15791LLB file operation can be tricked to remove /tmp directory contentsmoby BuildKit
CVE-2026-15789Malicious client can bypass destination directory validation on local sources uploadmoby BuildKit
CVE-2026-15788WCOW cache mount source selector resolves NTFS junctions outside of cache rootmoby BuildKit