CVE Tools

Mobyproject

9 CVEs tracked since 2023. Since Feb 2023, none of them reached CISA KEV.

Mobyproject CVEs per month

Feb 2023 to Jan 2024. Point at a month, or focus the strip and use the arrow keys.
Mobyproject CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-0250
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-0140

Products

The products that kept showing up in Mobyproject's monthly top three, with their CVEs summed over those months.

  1. Hyperkit51 month
  2. Buildkit41 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Mobyproject.

  1. CVE-2026-15793Git source checkout from a bundle file could lead to command injection7.5
  2. CVE-2026-15792Possible panic when incorrect parameters sent from frontend7.5
  3. CVE-2026-15789Malicious client can bypass destination directory validation on local sources upload7.5
  4. CVE-2026-15791LLB file operation can be tricked to remove /tmp directory contents7.5
  5. CVE-2026-15788WCOW cache mount source selector resolves NTFS junctions outside of cache root7.5
  6. CVE-2026-42306Moby: Race condition in docker cp allows bind mount redirection to host path7.2
  7. CVE-2026-41568Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap6.1
  8. CVE-2026-33748BuildKit Git URL subdir component can cause access to restricted files7.5
  9. CVE-2026-33747BuildKit vulnerable to malicious frontend causing file escape outside of storage root8.4
  10. CVE-2025-54410Moby's Firewalld reload removes bridge network isolation3.3
  11. CVE-2025-54388Moby's Firewalld reload makes published container ports accessible from remote hosts4.6
  12. CVE-2024-36623moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application ...8.1
  13. CVE-2024-36621moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resu...6.5
  14. CVE-2024-36620moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.6.5
  15. CVE-2024-32473Moby IPv6 enabled on IPv4-only network interfaces4.7

The record

Peak rank
#126 in Feb 2023
Busiest month shown
Feb 2023, 5 CVEs
Months with a KEV entry
0 since Feb 2023
Monthly snapshots
2 since 2023
Mobyproject's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store