CVE-2026-41567
Vulnerability Summary
Timeline
Description
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images
CVSS Metrics
- v3.1•HIGH•Score: 7.2CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.16%• Percentile: 6%
Techniques & Countermeasures
- CWE-427•Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Affected Systems
- chainguard•agentbeat
all
- chainguard•agentbeat-fips
all
- chainguard•amazon-cloudwatch-agent
all
- chainguard•amazon-cloudwatch-agent-fips
all
- chainguard•amazon-cloudwatch-agent-operator
< 3.6.0-r0
- chainguard•amazon-cloudwatch-agent-operator-fips
< 3.6.0-r0
- chainguard•amazon-ecs-agent
all
- chainguard•amazon-ecs-agent-fips
all
- chainguard•auditbeat-8.17
all
- chainguard•auditbeat-8.19
< 8.19.17-r0
- chainguard•auditbeat-9.0
all
- chainguard•auditbeat-9.1
all
- chainguard•auditbeat-9.2
all
- chainguard•auditbeat-9.3
< 9.3.6-r0
- chainguard•auditbeat-9.4
< 9.4.3-r0
- chainguard•auditbeat-fips-8.17
all
- chainguard•auditbeat-fips-8.19
< 8.19.17-r0
- chainguard•auditbeat-fips-9.0
all
- chainguard•auditbeat-fips-9.1
all
- chainguard•auditbeat-fips-9.2
all
- chainguard•auditbeat-fips-9.3
< 9.3.6-r0
- chainguard•auditbeat-fips-9.4
< 9.4.3-r0
- chainguard•aws-otel-collector
< 0.48.0-r0
- chainguard•aws-otel-collector-fips
< 0.48.0-r0
- chainguard•buildah
< 1.44.0-r0
- chainguard•buildah-fips
< 1.44.0-r0
- chainguard•cg
< 0
- chainguard•chainctl
all
- chainguard•chainctl-fips
all
- chainguard•chainloop-control-plane
< 1.100.8-r0
- chainguard•chainloop-control-plane-fips
< 1.100.8-r0
- chainguard•chaos-mesh
all
- chainguard•chaos-mesh-daemon
all
- chainguard•chaos-mesh-dashboard
all
- chainguard•chaos-mesh-fips
all
- chainguard•chaos-mesh-fips-daemon
all
- chainguard•chaos-mesh-fips-dashboard
all
- chainguard•cloudbeat-8.17
< 0
- chainguard•cloudbeat-8.19
all
- chainguard•cloudbeat-9.0
< 0
- chainguard•cloudbeat-9.1
all
- chainguard•cloudbeat-9.2
all
- chainguard•cloudbeat-9.3
< 9.3.8-r0
- chainguard•cloudbeat-9.4
< 9.4.4-r0
- chainguard•cloudbeat-fips-8.17
< 0
- chainguard•cloudbeat-fips-8.19
all
- chainguard•cloudbeat-fips-9.0
< 0
- chainguard•cloudbeat-fips-9.1
all
- chainguard•cloudbeat-fips-9.2
all
- chainguard•cloudbeat-fips-9.3
< 9.3.8-r0
Showing first 50 affected entries in server-rendered view.
References (13)
- https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r
- https://github.com/moby/moby
- https://nvd.nist.gov/vuln/detail/CVE-2026-41567
- https://access.redhat.com/security/cve/CVE-2026-41567
- https://bugzilla.redhat.com/show_bug.cgi?id=2485356
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json
- https://access.redhat.com/errata/RHSA-2026:37387
- https://access.redhat.com/errata/RHSA-2026:41030
- https://access.redhat.com/errata/RHSA-2026:42852
- https://access.redhat.com/errata/RHSA-2026:51057
- https://access.redhat.com/errata/RHSA-2026:44622
- https://security-tracker.debian.org/tracker/CVE-2026-41567
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41567.json