CVE-2026-41568None▾ SunlitRace condition in 'docker cp' in github.com/docker/docker allows creation of arbitrary files
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.1%
A race condition in the Docker daemon allows an attacker to create arbitrary empty files on the host system during a "docker cp" operation by swapping a destination path with a symbolic link.
The affected code is in the daemon package, specifically the openContainerFS and createIfNotExists methods. This is daemon-owned, Linux-specific code and is not intended for external use as a Go library.
github.com/docker/dockergithub.com/moby/mobygithub.com/moby/moby/v2 < 2.0.0-beta.14Upgrade to a patched release:
github.com/moby/moby/v2 2.0.0-beta.14Connected by shared product, vendor, weakness, or advisory.
CVE-2021-41089Low· 2.8`docker cp` allows unexpected chmod of host files in Moby Docker Engine
GO-2022-0379NoneType confusion in github.com/docker/distribution
GHSA-qq97-vm5h-rrhgLow· 3.0OCI Manifest Type Confusion Issue
CVE-2021-41092Medium· 5.4Docker CLI leaks private registry credentials to registry-1.docker.io
CVE-2026-55887High· 8.7MCP Gateway allows easy and secure running and deployment of MCP servers
CVE-2026-79994High· 8.7The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname