---
id: CVE-2026-41567
title: Moby is an open source container framework
summary: >-
  Moby is an open source container framework. In versions prior to 29.5.1 and in
  moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to
  a container via `PUT /containers/{id}/archive` or piped through `docker cp -`,
  …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-427
vendor: moby
product: moby/v2/daemon
affected:
  - moby/v2/daemon < 2.0.0-beta.14
  - docker_engine < 29.5.1
  - docker/daemon <= 28.5.2
patched:
  - multicluster_global_hub 1.4.5
  - multicluster_global_hub 1.6.5
  - openshift_developer_tools_and_services 1.6.3
  - openshift_data_foundation 4.22
  - multicluster_global_hub 1.5.3
published: '2026-06-05'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:19:53.313'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41567'
references:
  - url: 'https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:37387'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41030'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42852'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:44622'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:51057'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-41567'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2485356'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-41567'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41567'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-05T13:11:38.173928Z'
epss: 0.00161
epssPercentile: 0.05709
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/berdav/CVE-2026-41567'
  checkedAt: '2026-09-24T07:53:03.252Z'
exploitAvailable: true
scores:
  nvd: 7.2
  vendor: 7.5
  cna: 7.2
ingestedAt: '2026-07-06T17:44:51.177Z'
---

## Overview

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:41030** · Red Hat · fixed in: Multicluster Global Hub 1.4.5 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41030)
- **RHSA-2026:44622** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-07-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:44622)
- **RHSA-2026:51057** · Red Hat · fixed in: OpenShift Developer Tools and Services 1.6.3 · released 2026-08-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:51057)
- **RHSA-2026:37387** · Red Hat · fixed in: Red Hat Openshift Data Foundation 4.22 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37387)
- **RHSA-2026:42852** · Red Hat · fixed in: Red Hat multicluster global hub 1.5.3 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42852)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Multicluster Engine for Kubernetes, OpenShift Lightspeed, Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · no fix planned: Red Hat Ceph Storage 5, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, Red Hat Ceph Storage 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json)
