CVE-2024-36621: Mobyproject Moby

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

Affected products

Published 2024-11-29. Last modified 2026-06-17.