Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-x86f-5xw2-fm2r

3 месяца назад

Docker: `PUT /containers/{id}/archive` executes container binary on the host

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2026-41567

около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
EPSS: Низкий
redhat логотип

CVE-2026-41567

около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-41567

около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2026-41567

около 2 месяцев назад

Moby is an open source container framework. In versions prior to 29.5. ...

CVSS3: 7.2
EPSS: Низкий
redos логотип

ROS-20260625-73-0023

около 1 месяца назад

Уязвимость docker-ce

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2026-09696

3 месяца назад

Уязвимость программного средства для создания систем контейнерной изоляции Moby, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 7.2
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21060-1

около 1 месяца назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2692-1

около 1 месяца назад

Security update for docker

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21205-1

около 1 месяца назад

Security update for docker-stable

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-x86f-5xw2-fm2r

Docker: `PUT /containers/{id}/archive` executes container binary on the host

CVSS3: 7.2
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-41567

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-41567

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-41567

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-41567

Moby is an open source container framework. In versions prior to 29.5. ...

CVSS3: 7.2
0%
Низкий
около 2 месяцев назад
redos логотип
ROS-20260625-73-0023

Уязвимость docker-ce

CVSS3: 7.2
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-09696

Уязвимость программного средства для создания систем контейнерной изоляции Moby, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

CVSS3: 7.2
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21060-1

Security update for docker

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2692-1

Security update for docker

около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21205-1

Security update for docker-stable

около 1 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.