CVE-2026-41567

Aliases:GHSA-x86f-5xw2-fm2rGO-2026-5746
Awaiting Analysis
Published: 05 Jun 2026, 00:35
Last modified:22 Jul 2026, 12:08

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.2 HIGH
v3.1 (cve.org)
EPSS Score
0.15% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jun 2026, 00:35
Published
Vulnerability first disclosed
22 Jul 2026, 12:08
Last Modified
Vulnerability information updated

Description

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS Metrics

  • v3.1HIGHScore: 7.2CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.15% Percentile: 5%

Techniques & Countermeasures

  • CWE-427Uncontrolled Search Path Element

    The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Affected Systems

  • dockerdocker/daemon

    ≤ 28.5.2

  • github.com/dockerdocker

    ≤ 28.5.2 | all

  • github.com/mobymoby

    ≤ 28.5.2 | all

  • github.com/moby/mobyv2

    < 2.0.0-beta.14

  • mobydocker engine

    < 29.5.1

  • mobymoby/v2/daemon

    < 2.0.0-beta.14

References (9)