Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41567

33
FAUCET Score

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

First published: Jun 5, 2026Last modified: Jun 5, 2026

Impacted Technologies

VendorProductVersion(s)CPE
MobyDocker Engine
< 29.5.1CNA affected
DockerDocker/Daemon
<= 28.5.2CNA affected
MobyMoby/V2/Daemon
< 2.0.0-beta.14CNA affected

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
5.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 47th percentile among its peer group of 39 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.2 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.5 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/moby/moby/v2Fixed in: 2.0.0-beta.14

Vendor Advisories (1)

goGHSA-x86f-5xw2-fm2rhigh

Docker: `PUT /containers/{id}/archive` executes container binary on the host

May 18, 2026

References

access.redhat.com / errata/RHSA-2026:37387
access.redhat.com / errata/RHSA-2026:41030
access.redhat.com / errata/RHSA-2026:42852
access.redhat.com / errata/RHSA-2026:44622
access.redhat.com / security/cve/CVE-2026-41567
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41567.json
github.com / moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r