CVE-2026-41567: Docker Docker/daemon

High severity, CVSS 7.2. EPSS: 0.2% chance of exploitation in the next 30 days.

Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

Affected products

  • Docker Docker/daemon: up to and including 28.5.2
  • Moby Docker Engine: before 29.5.1 (fixed in 29.5.1)
  • Moby moby/v2/daemon: before 2.0.0-beta.14 (fixed in 2.0.0-beta.14)
  • Red Hat Exploit Intelligence
  • Red Hat Multicluster Engine For Kubernetes
  • Red Hat Multicluster Global Hub 1.4.5: before 1784060681 (fixed in 1784060681)
  • Red Hat Multicluster Global Hub 1.6.5: before 1784561376 (fixed in 1784561376)
  • Red Hat Openshift Developer Tools And Services 1.6.3: before 1784727697 (fixed in 1784727697); before 1784728036 (fixed in 1784728036)
  • Red Hat Openshift Lightspeed
  • Red Hat Red Hat Advanced Cluster Management For Kubernetes 2
  • Red Hat Red Hat Ceph Storage 5
  • Red Hat Red Hat Ceph Storage 7
  • Red Hat Red Hat Ceph Storage 8
  • Red Hat Red Hat Ceph Storage 9
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images
  • Red Hat Red Hat Multicluster Global Hub 1.5.3: before 1784562060 (fixed in 1784562060)
  • Red Hat Red Hat Openshift Ai Rhoai
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Data Foundation 4.22: before 1782932114 (fixed in 1782932114); before 1782931768 (fixed in 1782931768); before 1782932104 (fixed in 1782932104); before 1783536000 (fixed in 1783536000); before 1783535989 (fixed in 1783535989); before 1783536515 (fixed in 1783536515); …
  • Red Hat Red Hat Openshift Distributed Tracing 3

Published 2026-06-05. Last modified 2026-09-09.