Skip to content
VulniPulse
High7.2Docker Updated

High [CVE-2026-41567] Docker Engine: Moby is an open source container framework

This high-severity Docker advisory covers CVE-2026-41567 affecting moby/v2/daemon, Docker Engine, docker/daemon.

CVE-2026-41567 Published Jun 5, 2026Updated by vendor Aug 24, 2026
Affected products & platforms
DockerDocker Engine / Moby
Open vendor advisory

Android app · Google Play

Monitor future Docker CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Moby is an open source container framework.

In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations.

A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14.

Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

Affected products named by the advisory: moby/v2/daemon; docker/daemon.

Affected versions
  • before 29.5.1
  • before 2.0.0-beta.14

NVD record · high-confidence parse· fetched 1 month ago·verify at source

Fixed versions
  • 29.5.1
  • 2.0.0-beta.14

NVD record · high-confidence parse· fetched 1 month ago·verify at source

Mitigation checklist

Temporary workarounds
  • Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

NVD record · high-confidence parse· fetched 1 month ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.