VulnSea

moby has 13 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/moby/moby (6), github.com/moby/buildkit (4), buildkit (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
3 prev 2

Products

  • github.com/moby/moby 6
  • github.com/moby/buildkit 4
  • buildkit 1
  • moby/v2/daemon 1
  • spdystream 1
13
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

moby vulnerabilities

CVEs affecting moby, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-75593High· 7.2
1mo ago

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …

Twilightmoby · buildkitEPSS 0.54%via NVD
CVE-2026-61711Medium
1mo ago

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

Sunlitmoby · github.com/moby/buildkitEPSS 0.36%via OSV
CVE-2026-61712Low
1mo ago

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

Sunlitmoby · github.com/moby/buildkitEPSS 0.40%via OSV
CVE-2026-41567High· 7.2PoC
3mo ago

Moby is an open source container framework

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …

Midnightmoby · moby/v2/daemonEPSS 0.16%via NVD
CVE-2026-35469Medium· 6.5⚖ disputed
5mo ago

spdystream is a Go library for multiplexing streams over SPDY connections

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are…

Sunlitmoby · spdystreamEPSS 0.66%via NVD
CVE-2026-33748High· 7.5
6mo ago

BuildKit Git URL subdir component can cause access to restricted files

BuildKit Git URL subdir component can cause access to restricted files

Twilightmoby · github.com/moby/buildkitEPSS 0.46%via OSV
CVE-2024-36621Medium· 6.5
1y ago

Moby Race Condition vulnerability

Moby Race Condition vulnerability

Sunlitmoby · github.com/moby/mobyEPSS 0.63%via OSV
CVE-2022-24769Medium· 5.9
2y ago

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

Moby (Docker Engine) started with non-empty inheritable Linux process capabilities

Sunlitmoby · github.com/moby/mobyEPSS 0.49%via OSV
CVE-2020-27534Medium· 5.3
2y ago

Path Traversal in Moby builder

Path Traversal in Moby builder

Sunlitmoby · github.com/moby/mobyEPSS 1.7%via OSV
CVE-2024-23652Critical· 10.0PoC
2y ago

BuildKit vulnerable to possible host system access from mount stub cleaner

BuildKit vulnerable to possible host system access from mount stub cleaner

Abyssalmoby · github.com/moby/buildkitEPSS 2.1%via OSV
CVE-2021-21284Medium· 6.8
2y ago

moby Access to remapped root allows privilege escalation to real root

moby Access to remapped root allows privilege escalation to real root

Sunlitmoby · github.com/moby/mobyEPSS 1.1%via OSV
CVE-2021-21285Medium· 6.5
2y ago

moby docker daemon crash during image pull of malicious image

moby docker daemon crash during image pull of malicious image

Sunlitmoby · github.com/moby/mobyEPSS 3.3%via OSV
CVE-2021-41091Medium· 5.9PoC
2y ago

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Moby (Docker Engine) Insufficiently restricted permissions on data directory

Twilightmoby · github.com/moby/mobyEPSS 2.8%via OSV
moby vulnerabilities (CVEs) · VulnSea