High [CVE-2026-41567] Docker Engine: Moby is an open source container framework
This high-severity Docker advisory covers CVE-2026-41567 affecting moby/v2/daemon, Docker Engine, docker/daemon.
Android app · Google Play
Monitor future Docker CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Moby is an open source container framework.
In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations.
A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14.
Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images
Affected products named by the advisory: moby/v2/daemon; docker/daemon.
- before 29.5.1
- before 2.0.0-beta.14
NVD record · high-confidence parse· fetched 1 month ago·verify at source
- 29.5.1
- 2.0.0-beta.14
NVD record · high-confidence parse· fetched 1 month ago·verify at source
Mitigation checklist
- Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images
NVD record · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.