moby has 13 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: github.com/moby/moby (6), github.com/moby/buildkit (4), buildkit (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 2
Products
- github.com/moby/moby 6
- github.com/moby/buildkit 4
- buildkit 1
- moby/v2/daemon 1
- spdystream 1
Worst active — by depth score
CVE-2024-23652Critical· 10.0BuildKit vulnerable to possible host system access from mount stub cleaner67CVE-2026-41567High· 7.2Moby is an open source container framework52CVE-2021-41091Medium· 5.9Moby (Docker Engine) Insufficiently restricted permissions on data directory45CVE-2026-33748High· 7.5BuildKit Git URL subdir component can cause access to restricted files41CVE-2026-75593High· 7.2BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner40
moby vulnerabilities
CVEs affecting moby, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-75593High· 7.2BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from …
CVE-2026-61711MediumBuildKit: Custom frontend could bypass Seccomp/AppArmor
BuildKit: Custom frontend could bypass Seccomp/AppArmor
CVE-2026-61712LowBuildKit has a possible runtime DoS via unbounded group parsing
BuildKit has a possible runtime DoS via unbounded group parsing
CVE-2026-41567High· 7.2PoCMoby is an open source container framework
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, …
CVE-2026-35469Medium· 6.5⚖ disputedspdystream is a Go library for multiplexing streams over SPDY connections
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are…
CVE-2026-33748High· 7.5BuildKit Git URL subdir component can cause access to restricted files
BuildKit Git URL subdir component can cause access to restricted files
CVE-2024-36621Medium· 6.5Moby Race Condition vulnerability
Moby Race Condition vulnerability
CVE-2022-24769Medium· 5.9Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
CVE-2020-27534Medium· 5.3Path Traversal in Moby builder
Path Traversal in Moby builder
CVE-2024-23652Critical· 10.0PoCBuildKit vulnerable to possible host system access from mount stub cleaner
BuildKit vulnerable to possible host system access from mount stub cleaner
CVE-2021-21284Medium· 6.8moby Access to remapped root allows privilege escalation to real root
moby Access to remapped root allows privilege escalation to real root
CVE-2021-21285Medium· 6.5moby docker daemon crash during image pull of malicious image
moby docker daemon crash during image pull of malicious image
CVE-2021-41091Medium· 5.9PoCMoby (Docker Engine) Insufficiently restricted permissions on data directory
Moby (Docker Engine) Insufficiently restricted permissions on data directory