[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-36621":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":28,"aliases":29,"duplicate_of":9,"upstream":32,"downstream":33,"duplicates":42,"related":43,"reserved_at":9,"published_at":57,"modified_at":58,"state":59,"summary":60,"references_raw":69,"kevs":103,"epss":104,"epss_history":107,"metrics":376,"affected":389},"CVE-2024-36621","moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-362","Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')","The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.","weakness","Draft","Class","Medium",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-26","Leveraging Race Conditions",[],{"id":25,"name":26,"techniques":27},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],[],[30,31],"GHSA-2mj3-vfvx-fc43","GO-2024-3304",[],[34,36,38,40],{"_key":35},"OPENSUSE-SU-2024:14567-1",{"_key":37},"USN-7474-1",{"_key":39},"DEBIAN-CVE-2024-36621",{"_key":41},"UBUNTU-CVE-2024-36621",[],[44,45,47,49,51,53,55],{"_key":35},{"_key":46},"CGA-3HW2-226P-HHHH",{"_key":48},"CGA-5J94-HQ8C-4597",{"_key":50},"CGA-8WWV-R3C4-26C8",{"_key":52},"CGA-9WPW-XJ7F-CPX9",{"_key":54},"CGA-RJ2H-QGVQ-F849",{"_key":56},"CGA-MMPP-XMW8-4R94","2024-11-29T00:00:00.000Z","2024-12-04T17:13:36.018Z","Analyzed",{"cisa_kev":61,"cisa_ransomware":61,"cisa_vendor":9,"epss_severity":62,"epss_score":63,"severity":64,"severity_score":65,"severity_version":66,"severity_source":67,"severity_vector":68,"severity_status":59},false,"low",0.00053,"medium",6.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",[70,79,84,89,94,98],{"url":71,"sources":72,"tags":75},"https://github.com/moby/moby/commit/37545cc644344dcb576cba67eb7b6f51a463d31e",[67,73,74],"nvd","osv_go",[76,77,78],"Patch","WEB","FIX",{"url":80,"sources":81,"tags":82},"https://github.com/moby/moby/blob/v25.0.5/builder/builder-next/adapters/snapshot/layer.go#L24",[67,73,74],[83,77],"Product",{"url":85,"sources":86,"tags":87},"https://gist.github.com/1047524396/5d44459edab5fafcdf86b43909b81135",[67,73,74],[88,77],"Third Party Advisory",{"url":90,"sources":91,"tags":92},"https://nvd.nist.gov/vuln/detail/CVE-2024-36621",[74],[93],"Advisory",{"url":95,"sources":96,"tags":97},"https://github.com/advisories/GHSA-2mj3-vfvx-fc43",[74],[93],{"url":99,"sources":100,"tags":101},"https://github.com/moby/moby",[74],[102],"PACKAGE",[],{"date":105,"score":63,"percentile":106},"2026-06-04",0.16827,[108,112,115,118,121,124,127,130,133,136,138,141,144,147,150,154,157,160,163,166,169,172,174,177,180,183,186,189,192,195,198,201,204,207,210,213,216,218,221,224,227,230,233,236,239,242,245,248,251,253,256,259,262,265,268,270,273,276,279,282,285,288,291,294,297,301,305,308,311,314,317,320,322,325,328,331,334,337,340,343,346,349,352,355,358,361,364,367,370,373],{"date":109,"score":110,"percentile":111},"2025-11-04",0.0022,0.44588,{"date":113,"score":110,"percentile":114},"2025-11-05",0.44582,{"date":116,"score":110,"percentile":117},"2025-11-06",0.44594,{"date":119,"score":110,"percentile":120},"2025-11-07",0.44621,{"date":122,"score":110,"percentile":123},"2025-11-08",0.44618,{"date":125,"score":110,"percentile":126},"2025-11-09",0.44599,{"date":128,"score":110,"percentile":129},"2025-11-10",0.44557,{"date":131,"score":110,"percentile":132},"2025-11-11",0.44573,{"date":134,"score":110,"percentile":135},"2025-11-12",0.44607,{"date":137,"score":110,"percentile":120},"2025-11-13",{"date":139,"score":110,"percentile":140},"2025-11-14",0.44635,{"date":142,"score":110,"percentile":143},"2025-11-15",0.44628,{"date":145,"score":110,"percentile":146},"2025-11-16",0.4461,{"date":148,"score":110,"percentile":149},"2025-11-17",0.4458,{"date":151,"score":152,"percentile":153},"2025-11-18",0.00304,0.50739,{"date":155,"score":152,"percentile":156},"2025-11-19",0.5075,{"date":158,"score":152,"percentile":159},"2025-11-20",0.50737,{"date":161,"score":110,"percentile":162},"2025-11-21",0.44577,{"date":164,"score":110,"percentile":165},"2025-11-22",0.44576,{"date":167,"score":110,"percentile":168},"2025-11-23",0.44555,{"date":170,"score":110,"percentile":171},"2025-11-24",0.44547,{"date":173,"score":110,"percentile":129},"2025-11-25",{"date":175,"score":110,"percentile":176},"2025-11-26",0.44558,{"date":178,"score":110,"percentile":179},"2025-11-27",0.44566,{"date":181,"score":110,"percentile":182},"2025-11-28",0.44529,{"date":184,"score":110,"percentile":185},"2025-11-29",0.44512,{"date":187,"score":110,"percentile":188},"2025-11-30",0.44495,{"date":190,"score":110,"percentile":191},"2025-12-01",0.44632,{"date":193,"score":110,"percentile":194},"2025-12-02",0.44647,{"date":196,"score":110,"percentile":197},"2025-12-03",0.44642,{"date":199,"score":110,"percentile":200},"2025-12-04",0.44497,{"date":202,"score":110,"percentile":203},"2025-12-05",0.44523,{"date":205,"score":110,"percentile":206},"2025-12-06",0.44518,{"date":208,"score":110,"percentile":209},"2025-12-07",0.445,{"date":211,"score":110,"percentile":212},"2025-12-08",0.44507,{"date":214,"score":110,"percentile":215},"2025-12-09",0.44543,{"date":217,"score":110,"percentile":146},"2025-12-10",{"date":219,"score":110,"percentile":220},"2025-12-11",0.44637,{"date":222,"score":110,"percentile":223},"2025-12-12",0.44665,{"date":225,"score":110,"percentile":226},"2025-12-13",0.44645,{"date":228,"score":110,"percentile":229},"2025-12-14",0.4462,{"date":231,"score":110,"percentile":232},"2025-12-15",0.44602,{"date":234,"score":110,"percentile":235},"2025-12-16",0.44623,{"date":237,"score":110,"percentile":238},"2025-12-17",0.44663,{"date":240,"score":110,"percentile":241},"2025-12-18",0.44705,{"date":243,"score":110,"percentile":244},"2025-12-19",0.44719,{"date":246,"score":110,"percentile":247},"2025-12-20",0.44689,{"date":249,"score":110,"percentile":250},"2025-12-21",0.44656,{"date":252,"score":110,"percentile":140},"2025-12-22",{"date":254,"score":110,"percentile":255},"2025-12-23",0.44634,{"date":257,"score":110,"percentile":258},"2025-12-24",0.44644,{"date":260,"score":110,"percentile":261},"2025-12-25",0.44696,{"date":263,"score":110,"percentile":264},"2025-12-26",0.44676,{"date":266,"score":110,"percentile":267},"2025-12-27",0.44695,{"date":269,"score":110,"percentile":232},"2025-12-28",{"date":271,"score":110,"percentile":272},"2025-12-29",0.44585,{"date":274,"score":110,"percentile":275},"2025-12-30",0.44578,{"date":277,"score":110,"percentile":278},"2025-12-31",0.44625,{"date":280,"score":110,"percentile":281},"2026-01-01",0.4477,{"date":283,"score":110,"percentile":284},"2026-01-02",0.44748,{"date":286,"score":110,"percentile":287},"2026-01-03",0.44734,{"date":289,"score":110,"percentile":290},"2026-01-04",0.44569,{"date":292,"score":110,"percentile":293},"2026-01-05",0.44553,{"date":295,"score":110,"percentile":296},"2026-01-06",0.44554,{"date":298,"score":299,"percentile":300},"2026-01-07",0.00062,0.19662,{"date":302,"score":303,"percentile":304},"2026-01-08",0.00055,0.1765,{"date":306,"score":303,"percentile":307},"2026-01-09",0.17656,{"date":309,"score":63,"percentile":310},"2026-01-10",0.16816,{"date":312,"score":63,"percentile":313},"2026-01-11",0.16782,{"date":315,"score":63,"percentile":316},"2026-01-12",0.16742,{"date":318,"score":63,"percentile":319},"2026-01-13",0.16725,{"date":321,"score":63,"percentile":313},"2026-01-14",{"date":323,"score":63,"percentile":324},"2026-01-15",0.16783,{"date":326,"score":63,"percentile":327},"2026-01-16",0.16829,{"date":329,"score":63,"percentile":330},"2026-01-17",0.16838,{"date":332,"score":63,"percentile":333},"2026-01-18",0.1678,{"date":335,"score":63,"percentile":336},"2026-01-19",0.16722,{"date":338,"score":63,"percentile":339},"2026-01-20",0.16694,{"date":341,"score":63,"percentile":342},"2026-01-21",0.16672,{"date":344,"score":63,"percentile":345},"2026-01-22",0.16609,{"date":347,"score":63,"percentile":348},"2026-01-23",0.16687,{"date":350,"score":63,"percentile":351},"2026-01-24",0.16714,{"date":353,"score":63,"percentile":354},"2026-01-25",0.16646,{"date":356,"score":63,"percentile":357},"2026-01-26",0.16543,{"date":359,"score":63,"percentile":360},"2026-01-27",0.16533,{"date":362,"score":63,"percentile":363},"2026-01-28",0.16542,{"date":365,"score":63,"percentile":366},"2026-01-29",0.16515,{"date":368,"score":63,"percentile":369},"2026-01-30",0.16523,{"date":371,"score":63,"percentile":372},"2026-01-31",0.16538,{"date":374,"score":63,"percentile":375},"2026-02-01",0.16558,[377,382,384],{"source":67,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":378,"cvss_v4_0":9},{"baseScore":65,"baseSeverity":379,"vectorString":68,"impactScore":380,"exploitabilityScore":381},"MEDIUM",6,7.2,{"source":73,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":383,"cvss_v4_0":9},{"baseScore":65,"baseSeverity":379,"vectorString":68,"impactScore":380,"exploitabilityScore":381},{"source":74,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":385,"cvss_v4_0":386},{"baseScore":65,"baseSeverity":9,"vectorString":68,"impactScore":380,"exploitabilityScore":381},{"baseScore":387,"baseSeverity":9,"vectorString":388,"impactScore":9,"exploitabilityScore":9},8.7,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",[390,406],{"ecosystem":391,"name":392,"vendor":393,"product":394,"cpe_part":9,"purl_type":395,"purl_namespace":393,"purl_name":394,"source":9,"versions":396},"Go","github.com/moby/moby","github.com/moby","moby","golang",[397,403],{"version":398,"is_range":399,"range_type":400,"version_start":9,"version_start_type":9,"version_end":401,"version_end_type":402,"fixed_in":9},"lt26_0_0",true,"semver","26.0.0","excluding",{"version":404,"is_range":399,"range_type":400,"version_start":9,"version_start_type":9,"version_end":405,"version_end_type":402,"fixed_in":9},"lt26_0_0+incompatible","26.0.0+incompatible",{"ecosystem":9,"name":394,"vendor":407,"product":394,"cpe_part":408,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":409},"mobyproject","a",[410],{"version":411,"is_range":61,"range_type":412,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"25.0.5","cpe"]