Moby Project maintains a narrow portfolio of container runtime and build infrastructure components—including Moby, BuildKit, and HyperKit—that are foundational to Docker and other container platforms, making them highly visible despite a small product count. Vulnerabilities affecting this vendor gravitate toward a moderate severity profile, reflecting the critical access level that container runtimes and build systems command within orchestrated environments. The recurring weakness classes center on concurrency and synchronization issues, error handling, path traversal, and null-pointer dereferences, patterns that are characteristic of low-level systems code managing process isolation, filesystem access, and resource sharing at scale. Defenders should treat Moby Project advisories as infrastructure-tier priorities and inventory downstream products that bundle these components, since fixes in the runtime or build layer often require coordinated container platform updates. Live severity, exploitation activity, and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mobyproject over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33747CRITICAL BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit fronten | Mar 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2024-23653CRITICAL BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build steps, BuildKit al | Jan 31, 2024 | 9.8 | 32 | NO | NO |
CVE-2024-23652CRITICAL BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount | Jan 31, 2024 | 9.1 | 30 | NO | NO |
CVE-2026-42306HIGH Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and prior, and Moby Daemon prior to version 2.0.0-beta.14, a rac | Jun 12, 2026 | 7.2 | 28 | NO | NO |
CVE-2023-28840HIGH Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The M | Apr 4, 2023 | 8.7 | 28 | NO | NO |
CVE-2026-33748HIGH BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL f | Mar 27, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-23651HIGH BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the sam | Jan 31, 2024 | 7.4 | 25 | NO | NO |
CVE-2021-32845HIGH HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of HyperKit, the implementation of `qnotify` at `pci_vtrnd_notify` f | Feb 17, 2023 | 7.8 | 25 | NO | NO |
CVE-2024-24557HIGH Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratc | Feb 1, 2024 | 7.8 | 24 | NO | NO |
CVE-2021-32846HIGH HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vtsock_proc_tx` in `virtio-sock` can lead to to uninitialized m | Feb 17, 2023 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mobyproject.
Media articles that mention a CVE ID that affects a product developed by Mobyproject — matched by CVE ID, not by vendor name.