{"id":"CVE-2026-41567","aliases":["GHSA-x86f-5xw2-fm2r","GO-2026-5746"],"url":"https://o3.security/vulnerability/CVE-2026-41567","summary":"Docker: `PUT /containers/{id}/archive` executes container binary on the host","details":"Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images","published":"2026-06-05T00:35:50.563Z","modified":"2026-08-12T03:51:12.292100126Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N"},"epss":{"score":0.00161,"percentile":0.05727,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/moby/moby/v2","fixedVersion":"2.0.0-beta.14"},{"ecosystem":"Go","name":"github.com/docker/docker","fixedVersion":null},{"ecosystem":"Go","name":"github.com/moby/moby","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41567.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37387"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:41030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:42852"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:44622"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:51057"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-41567"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41567.json"},{"type":"ADVISORY","url":"https://github.com/moby/moby/security/advisories/GHSA-x86f-5xw2-fm2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41567"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2485356"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.292100126Z"}}