๐Ÿ” CVE Alert

CVE-2026-41567

HIGH 7.2

Docker: `PUT /containers/{id}/archive` executes container binary on the host

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

CWE CWE-427
Vendor moby
Product moby/v2/daemon
Published Jun 5, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for moby moby/v2/daemon

Be the first to know when new high vulnerabilities affecting moby moby/v2/daemon are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

moby / moby/v2/daemon
< 2.0.0-beta.14
moby / Docker Engine
< 29.5.1
docker / docker/daemon
<= 28.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r