mobyproject records
38 published records for vendor mobyproject.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 84.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-476 NULL Pointer Dereference3
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')3
- CWE-863 Incorrect Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-281 Improper Preservation of Permissions2
The weakness classes this vendor ships most often: where to look.
CWEAll records
38 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-23653Proof of concept | BuildKit interactive containers API does not validate entitlements checkmobyproject · buildkit · CWE-863 | Critical9.8 | — | 3.4% | Jan 31, 2024 |
39Monitor | CVE-2026-33747No exploit | BuildKit vulnerable to malicious frontend causing file escape outside of storage rootmobyproject · buildkit · CWE-22 | Critical9.8 | — | 0.6% | Mar 26, 2026 |
37Monitor | CVE-2024-23652Proof of concept | BuildKit possible host system access from mount stub cleanermobyproject · buildkit · CWE-22 | Critical9.1 | — | 2.5% | Jan 31, 2024 |
35Monitor | CVE-2023-28840No exploit | moby/moby's dockerd daemon encrypted overlay network may be unauthenticatedmobyproject · moby · CWE-420 | High8.7 | — | 2.6% | Apr 4, 2023 |
32Monitor | CVE-2024-36623No exploit | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent writmobyproject · moby · CWE-362 | High8.1 | — | 0.6% | Nov 29, 2024 |
32Monitor | CVE-2026-33748No exploit | BuildKit Git URL subdir component can cause access to restricted filesmobyproject · buildkit · CWE-22 | High8.2 | — | 0.5% | Mar 27, 2026 |
31Monitor | CVE-2021-32846No exploit | Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmobyproject · hyperkit · CWE-908 | High7.8 | — | 0.3% | Feb 17, 2023 |
31Monitor | CVE-2024-24557No exploit | Moby classic builder cache poisoningmobyproject · moby · CWE-345 | High7.8 | — | 0.3% | Feb 1, 2024 |
31Monitor | CVE-2021-32845No exploit | Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notifymobyproject · hyperkit · CWE-908 | High7.8 | — | 0.3% | Feb 17, 2023 |
30Monitor | CVE-2018-12608No exploit | An issue was discovered in Docker Moby before 17.06.0.mobyproject · moby · CWE-295 | High7.5 | — | 0.9% | Sep 10, 2018 |
30Monitor | CVE-2024-29018No exploit | External DNS requests from 'internal' networks could lead to data exfiltrationmobyproject · moby · CWE-669 | High7.5 | — | 0.8% | Mar 20, 2024 |
29Monitor | CVE-2024-23651No exploit | BuildKit possible race condition with accessing subpaths from cache mountsmobyproject · buildkit · CWE-362 | High7.4 | — | 0.9% | Jan 31, 2024 |
29Monitor | CVE-2026-15793No exploit | Git source checkout from a bundle file could lead to command injectionmobyproject · buildkit · CWE-88 | High7.3 | — | 0.3% | Jul 21, 2026 |
28Monitor | CVE-2026-42306No exploit | Moby: Race condition in docker cp allows bind mount redirection to host pathdocker · engine · CWE-61 | High7.2 | — | 0.1% | Jun 12, 2026 |
27Monitor | CVE-2023-28842No exploit | moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticatedmobyproject · moby · CWE-420 | Medium6.8 | — | 1.4% | Apr 4, 2023 |
27Monitor | CVE-2023-28841No exploit | moby/moby's dockerd daemon encrypted overlay network traffic may be unencryptedmobyproject · moby · CWE-311 | Medium6.8 | — | 0.7% | Apr 4, 2023 |
27Monitor | CVE-2026-15789No exploit | Malicious client can bypass destination directory validation on local sources uploadmobyproject · buildkit · CWE-22 | Medium6.9 | — | 0.3% | Jul 21, 2026 |
26Monitor | CVE-2021-41091Proof of concept | Insufficiently restricted permissions on data directory in Docker Enginemobyproject · moby · CWE-281 | Medium6.3 | — | 2.8% | Oct 4, 2021 |
26Monitor | CVE-2023-26054No exploit | Credentials inlined to Git URLs could end up in provenance attestation in BuildKitmobyproject · buildkit · CWE-200 | Medium6.5 | — | 1.0% | Mar 6, 2023 |
26Monitor | CVE-2024-36620No exploit | moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.mobyproject · moby · CWE-476 | Medium6.5 | — | 0.8% | Nov 29, 2024 |
26Monitor | CVE-2024-36621No exploit | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go.mobyproject · moby · CWE-362 | Medium6.5 | — | 0.6% | Nov 29, 2024 |
26Monitor | CVE-2021-32847No exploit | Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_txmobyproject · hyperkit · CWE-125 | Medium6.5 | — | 0.4% | Feb 20, 2023 |
26Monitor | CVE-2024-32473No exploit | Moby IPv6 enabled on IPv4-only network interfacesmobyproject · moby · CWE-668 | Medium6.5 | — | 0.4% | Apr 18, 2024 |
25Monitor | CVE-2022-36109No exploit | Moby vulnerability relating to supplementary group permissionsmobyproject · moby · CWE-863 | Medium6.3 | — | 1.0% | Sep 9, 2022 |
25Monitor | CVE-2021-41089No exploit | `docker cp` allows unexpected chmod of host filesmobyproject · moby · CWE-281 | Medium6.3 | — | 0.3% | Oct 4, 2021 |
- CVE-2024-2365340Plan
BuildKit interactive containers API does not validate entitlements check
CriticalCVSS 9.8Proof of conceptEPSS 3%mobyproject · buildkitJan 31, 2024
- CVE-2026-3374739Monitor
BuildKit vulnerable to malicious frontend causing file escape outside of storage root
CriticalCVSS 9.8No exploitEPSS 1%mobyproject · buildkitMar 26, 2026
- CVE-2024-2365237Monitor
BuildKit possible host system access from mount stub cleaner
CriticalCVSS 9.1Proof of conceptEPSS 2%mobyproject · buildkitJan 31, 2024
- CVE-2023-2884035Monitor
moby/moby's dockerd daemon encrypted overlay network may be unauthenticated
HighCVSS 8.7No exploitEPSS 3%mobyproject · mobyApr 4, 2023
- CVE-2024-3662332Monitor
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent writ
HighCVSS 8.1No exploitEPSS 1%mobyproject · mobyNov 29, 2024
- CVE-2026-3374832Monitor
BuildKit Git URL subdir component can cause access to restricted files
HighCVSS 8.2No exploitEPSS 1%mobyproject · buildkitMar 27, 2026
- CVE-2021-3284631Monitor
Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx
HighCVSS 7.8No exploitEPSS 0%mobyproject · hyperkitFeb 17, 2023
- CVE-2024-2455731Monitor
Moby classic builder cache poisoning
HighCVSS 7.8No exploitEPSS 0%mobyproject · mobyFeb 1, 2024
- CVE-2021-3284531Monitor
Moby HyperKit uninitialized memory use vtrnd pci_vtrnd_notify
HighCVSS 7.8No exploitEPSS 0%mobyproject · hyperkitFeb 17, 2023
- CVE-2018-1260830Monitor
An issue was discovered in Docker Moby before 17.06.0.
HighCVSS 7.5No exploitEPSS 1%mobyproject · mobySep 10, 2018
- CVE-2024-2901830Monitor
External DNS requests from 'internal' networks could lead to data exfiltration
HighCVSS 7.5No exploitEPSS 1%mobyproject · mobyMar 20, 2024
- CVE-2024-2365129Monitor
BuildKit possible race condition with accessing subpaths from cache mounts
HighCVSS 7.4No exploitEPSS 1%mobyproject · buildkitJan 31, 2024
- CVE-2026-1579329Monitor
Git source checkout from a bundle file could lead to command injection
HighCVSS 7.3No exploitEPSS 0%mobyproject · buildkitJul 21, 2026
- CVE-2026-4230628Monitor
Moby: Race condition in docker cp allows bind mount redirection to host path
HighCVSS 7.2No exploitEPSS 0%docker · engineJun 12, 2026
- CVE-2023-2884227Monitor
moby/moby's dockerd daemon encrypted overlay network with a single endpoint is unauthenticated
MediumCVSS 6.8No exploitEPSS 1%mobyproject · mobyApr 4, 2023
- CVE-2023-2884127Monitor
moby/moby's dockerd daemon encrypted overlay network traffic may be unencrypted
MediumCVSS 6.8No exploitEPSS 1%mobyproject · mobyApr 4, 2023
- CVE-2026-1578927Monitor
Malicious client can bypass destination directory validation on local sources upload
MediumCVSS 6.9No exploitEPSS 0%mobyproject · buildkitJul 21, 2026
- CVE-2021-4109126Monitor
Insufficiently restricted permissions on data directory in Docker Engine
MediumCVSS 6.3Proof of conceptEPSS 3%mobyproject · mobyOct 4, 2021
- CVE-2023-2605426Monitor
Credentials inlined to Git URLs could end up in provenance attestation in BuildKit
MediumCVSS 6.5No exploitEPSS 1%mobyproject · buildkitMar 6, 2023
- CVE-2024-3662026Monitor
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
MediumCVSS 6.5No exploitEPSS 1%mobyproject · mobyNov 29, 2024
- CVE-2024-3662126Monitor
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go.
MediumCVSS 6.5No exploitEPSS 1%mobyproject · mobyNov 29, 2024
- CVE-2021-3284726Monitor
Moby HyperKit uninitialized memory use in virtio-sock pci_vtsock_proc_tx
MediumCVSS 6.5No exploitEPSS 0%mobyproject · hyperkitFeb 20, 2023
- CVE-2024-3247326Monitor
Moby IPv6 enabled on IPv4-only network interfaces
MediumCVSS 6.5No exploitEPSS 0%mobyproject · mobyApr 18, 2024
- CVE-2022-3610925Monitor
Moby vulnerability relating to supplementary group permissions
MediumCVSS 6.3No exploitEPSS 1%mobyproject · mobySep 9, 2022
- CVE-2021-4108925Monitor
`docker cp` allows unexpected chmod of host files
MediumCVSS 6.3No exploitEPSS 0%mobyproject · mobyOct 4, 2021