{"id":"CVE-2026-41567","title":"Moby is an open source container framework","summary":"Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …","severity":"high","cvss":7.2,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-427"],"vendor":"moby","product":"moby/v2/daemon","affected":["moby/v2/daemon < 2.0.0-beta.14","docker_engine < 29.5.1","docker/daemon <= 28.5.2"],"patched":["multicluster_global_hub 1.4.5","multicluster_global_hub 1.6.5","openshift_developer_tools_and_services 1.6.3","openshift_data_foundation 4.22","multicluster_global_hub 1.5.3"],"published":"2026-06-05","updated":"2026-09-09","sourceUpdated":"2026-09-09T13:19:53.313","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41567","references":[{"url":"https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r","label":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:37387","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:41030","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:42852","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:44622","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:51057","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-41567","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485356","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-41567"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41567"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-06-05T13:11:38.173928Z"},"epss":0.00161,"epssPercentile":0.05705,"exploits":{"github":1,"githubRepos":["https://github.com/berdav/CVE-2026-41567"],"checkedAt":"2026-09-21T15:28:51.572Z"},"exploitAvailable":true,"scores":{"nvd":7.2,"vendor":7.5,"cna":7.2},"ingestedAt":"2026-07-06T17:44:51.177Z","slug":"CVE-2026-41567","body":"## Overview\n\nMoby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:41030** · Red Hat · fixed in: Multicluster Global Hub 1.4.5 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41030)\n- **RHSA-2026:44622** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44622)\n- **RHSA-2026:51057** · Red Hat · fixed in: OpenShift Developer Tools and Services 1.6.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51057)\n- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)\n- **RHSA-2026:42852** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42852)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Multicluster Engine for Kubernetes, OpenShift Lightspeed, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · no fix planned: Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json)","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":39.6,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":5186,"id":"CVE-2026-41567","ts":1788887252156,"field":"exploit_available","old":"false","new":"true"},{"seq":4069,"id":"CVE-2026-41567","ts":1788886368150,"field":"exploit_available","old":"true","new":"false"},{"seq":2858,"id":"CVE-2026-41567","ts":1788883034696,"field":"exploit_available","old":"false","new":"true"},{"seq":1887,"id":"CVE-2026-41567","ts":1788882437626,"field":"exploit_available","old":"true","new":"false"},{"seq":984,"id":"CVE-2026-41567","ts":1788881872162,"field":"exploit_available","old":"false","new":"true"}]}