Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-41110

41
FAUCET Score

CVE-2024-41110 is a critical authorization bypass vulnerability in certain versions of Docker Engine, allowing attackers to circumvent authorization plugins (AuthZ) by crafting special API requests that omit the body. This regression of a 2019 fix can lead to unauthorized actions and privilege escalation, impacting users relying on AuthZ plugins for access control. With a CVSS score of 9.9 (CRITICAL), the vulnerability has a low base likelihood of exploitation but high potential impact across confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
MobyMoby
= 27.1.0, >= 19.03.0, <= 19.03.15, >= 20.0.0, <= 20.10.27, >= 23.0.0, <= 23.0.14, >= 24.0.0, <= 24.0.9, >= 25.0.0, <= 25.0.5, >= 26.0.0, <= 26.0.2, >= 26.1.0, <= 26.1.14, >= 27.0.0, <= 27.0.3CNA affected

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
16.50%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1650 is in the 96th percentile among its peer group of 1,128 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

githubpatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 23.0.15
gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 26.1.5
gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 27.1.1
gopatch availablevia ghsa
Product: github.com/docker/dockerFixed in: 25.0.6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: 17272-16823Fixed in: 24.0.9-7
microsoftpatch availablevia msrc
Product: 19789-17086Fixed in: 24.0.9-7
microsoftpatch availablevia msrc
Product: 17674-17084Fixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: 19729-17084Fixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 24.0.9-7
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: cbl2 moby-engine 24.0.9-7 on CBL Mariner 2.0Fixed in: 24.0.9-7
microsoftpatch availablevia msrc
Product: cbl2 moby-engine 24.0.9-17 on CBL Mariner 2.0Fixed in: 24.0.9-7
microsoftpatch availablevia msrc
Product: azl3 moby-engine 25.0.3-5 on Azure Linux 3.0Fixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: azl3 moby-engine 25.0.3-13 on Azure Linux 3.0Fixed in: 25.0.3-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 24.0.9-7
redhatpatch availablevia redhat_api
Product: cert-manager operator for Red Hat OpenShift 1.14Fixed in: cert-manager/jetstack-cert-manager-rhel9:sha256:a594b7ff2fa1ff1b5e6764815d792ea546901edd566e8d2ec84674b3b1248bf1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: docker

Vendor Advisories (5)

microsoft2024-Sep/CVE-2024-41110

CVE-2024-41110

Sep 10, 2024
githubllm-github-d27101e386874770HIGH

AS-2024-005: Docker Engine

Aug 7, 2024
goGHSA-v23v-6jw2-98fqcritical

Authz zero length regression

Jul 30, 2024
redhatCVE-2024-41110Critical

moby: Authz zero length regression

Jul 23, 2024
microsoft2024-Jul/CVE-2024-41110Critical

Moby authz zero length regression

Jul 9, 2024

References

lists.debian.org / debian-lts-announce/2024/10/msg00009.html
security.netapp.com / advisory/ntap-20240802-0001
github.com / moby/moby/commit/411e817ddf710ff8e08fa193da80cb78af708191
github.com / moby/moby/commit/42f40b1d6dd7562342f832b9cd2adf9e668eeb76
github.com / moby/moby/commit/65cc597cea28cdc25bea3b8a86384b4251872919
github.com / moby/moby/commit/852759a7df454cbf88db4e954c919becd48faa9b
github.com / moby/moby/commit/a31260625655cff9ae226b51757915e275e304b0
github.com / moby/moby/commit/a79fabbfe84117696a19671f4aa88b82d0f64fc1
github.com / moby/moby/commit/ae160b4edddb72ef4bd71f66b975a1a1cc434f00
github.com / moby/moby/commit/ae2b3666c517c96cbc2adf1af5591a6b00d4ec0f
github.com / moby/moby/commit/cc13f952511154a2866bddbb7dddebfe9e83b801
github.com / moby/moby/commit/fc274cd2ff4cf3b48c91697fb327dd1fb95588fb
github.com / moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
docker.com / blog/docker-security-advisory-docker-engine-authz-plugin