VendorsMobyprojectmobyall versions
Vulnerabilities

Mobyproject Docker Moby

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2023-28840
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
Published 2023-04-04 · Modified
8.7EPSS 0.026
CVE-2024-36623
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
Published 2024-11-29 · Analyzed
8.1EPSS 0.006
CVE-2024-24557
Moby classic builder cache poisoning
Published 2024-02-01 · Modified
7.8EPSS 0.003
CVE-2018-12608
An issue was discovered in Docker Moby before 17.06.0. The Docker engine validated a client TLS certificate using both the configured client CA root certificate and all system roots on non-Windows systems. This allowed a client with any domain validated certificate signed by a system-trusted root CA (as opposed to one signed by the configured CA root certificate) to authenticate.
Published 2018-09-10 · Modified
7.5EPSS 0.009
CVE-2024-29018
External DNS requests from 'internal' networks could lead to data exfiltration
Published 2024-03-20 · Analyzed
7.5EPSS 0.008
CVE-2026-42306
Moby: Race condition in docker cp allows bind mount redirection to host path
Published 2026-06-12 · Analyzed
7.2EPSS 0.001
CVE-2023-28842
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
Published 2023-04-04 · Modified
6.8EPSS 0.014
CVE-2023-28841
moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted
Published 2023-04-04 · Modified
6.8EPSS 0.007
CVE-2024-36620
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
Published 2024-11-29 · Analyzed
6.5EPSS 0.008
CVE-2024-36621
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
Published 2024-11-29 · Analyzed
6.5EPSS 0.006
CVE-2024-32473
Moby IPv6 enabled on IPv4-only network interfaces
Published 2024-04-18 · Analyzed
6.5EPSS 0.004
CVE-2021-41091
Insufficiently restricted permissions on data directory in Docker Engine
Published 2021-10-04 · Modified
6.3EPSS 0.028
CVE-2018-10892
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
Published 2018-07-06 · Modified
6.3EPSS 0.011
CVE-2022-36109
Moby vulnerability relating to supplementary group permissions
Published 2022-09-09 · Modified
6.3EPSS 0.010
CVE-2021-41089
`docker cp` allows unexpected chmod of host files
Published 2021-10-04 · Modified
6.3EPSS 0.003
CVE-2026-41568
Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
Published 2026-06-12 · Analyzed
6.1EPSS 0.001
CVE-2017-16539
The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to trigger data loss (when certain older Linux kernels are used) by leveraging Docker container access to write a "scsi remove-single-device" line to /proc/scsi/scsi, aka SCSI MICDROP.
Published 2017-11-04 · Modified
5.9EPSS 0.018
CVE-2022-24769
Default inheritable capabilities for linux container should be empty
Published 2022-03-24 · Modified
5.9EPSS 0.005
CVE-2022-27652
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-18 · Modified
5.3EPSS 0.002
CVE-2025-54410
Moby's Firewalld reload removes bridge network isolation
Published 2025-07-30 · Analyzed
5.2EPSS 0.002
CVE-2025-54388
Moby's Firewalld reload makes published container ports accessible from remote hosts
Published 2025-07-30 · Analyzed
5.1EPSS 0.002