CVE-2026-41567: Docker Docker/daemon
High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images
Affected products
- Docker Docker/daemon: up to and including 28.5.2
- Moby Docker Engine: before 29.5.1 (fixed in 29.5.1)
- Moby moby/v2/daemon: before 2.0.0-beta.14 (fixed in 2.0.0-beta.14)
- Red Hat Exploit Intelligence
- Red Hat Multicluster Engine For Kubernetes
- Red Hat Multicluster Global Hub 1.4.5: before 1784060681 (fixed in 1784060681)
- Red Hat Multicluster Global Hub 1.6.5: before 1784561376 (fixed in 1784561376)
- Red Hat Openshift Developer Tools And Services 1.6.3: before 1784727697 (fixed in 1784727697); before 1784728036 (fixed in 1784728036)
- Red Hat Openshift Lightspeed
- Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
- Red Hat Red Hat Ceph Storage 5
- Red Hat Red Hat Ceph Storage 7
- Red Hat Red Hat Ceph Storage 8
- Red Hat Red Hat Ceph Storage 9
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images
- Red Hat Red Hat Multicluster Global Hub 1.5.3: before 1784562060 (fixed in 1784562060)
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Data Foundation 4.22: before 1782932114 (fixed in 1782932114); before 1782931768 (fixed in 1782931768); before 1782932104 (fixed in 1782932104); before 1783536000 (fixed in 1783536000); before 1783535989 (fixed in 1783535989); before 1783536515 (fixed in 1783536515); …
- Red Hat Red Hat Openshift Distributed Tracing 3
Published 2026-06-05. Last modified 2026-09-09.