CVE-2023-28842Medium· 6.8▾ SunlitA vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inj…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
1.4%
Last analysed / modified upstream
A vulnerability was found in Moby due to an unprotected alternate channel within encrypted overlay networks, which could allow a remote attacker to bypass security restrictions. By sending a specially crafted request, an attacker could inject arbitrary Ethernet frames into the encrypted overlay network by encapsulating them in VXLAN datagrams.
moby: Encrypted overlay network with a single endpoint is unauthenticated — rated Moderate by Red Hat. Released 2023-04-04, updated 2026-09-19.
Fixed:
Not affected:
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce https://access.redhat.com/errata/RHBA-2024:1246
Affected packages:
github.com/docker/docker >= 1.12.0, < 20.10.24github.com/docker/docker >= 23.0.0, < 23.0.3Patched in:
github.com/docker/docker 20.10.24github.com/docker/docker 23.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2023-28840High· 7.5Moby is an open source container framework developed by Docker Inc
CVE-2026-95897Medium· 5.5A security vulnerability has been detected in Dask up to 2026.8.0
CVE-2026-13087High· 8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c
CVE-2026-94640High· 7.5A flaw was found in rpcbind
CVE-2026-90462Medium· 5.4A flaw was found in SSSD
CVE-2026-95619High· 7.7A flaw was found in libstdc++