Search CVE reports


Toggle filters

1 – 10 of 19 results


CVE-2026-33990

Medium priority
Needs evaluation

(Docker Model Runner (DMR) is software used to manage, run, and deploy ...)

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34040

Medium priority
Needs evaluation

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33997

Medium priority
Needs evaluation

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54410

Medium priority
Needs evaluation

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-54388

Medium priority
Vulnerable

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.0 through 28.3.2, when...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Needs evaluation Needs evaluation Needs evaluation Needs evaluation
docker.io-app Vulnerable Vulnerable Not affected
Show less packages

CVE-2024-36623

Medium priority

Some fixes available 7 of 11

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed
docker.io-app Fixed Fixed Fixed
Show less packages

CVE-2024-36621

Medium priority

Some fixes available 7 of 12

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed
docker.io-app Fixed Fixed Fixed
Show less packages

CVE-2024-41110

High priority

Some fixes available 11 of 13

Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ)...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Fixed Fixed Fixed Fixed
docker.io-app Fixed Fixed Fixed
Show less packages

CVE-2024-32473

Medium priority

Some fixes available 2 of 4

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. In 26.0.0, IPv6 is not disabled on network interfaces, including those...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Not affected Not affected Not affected Not affected
docker.io-app Not affected Fixed Fixed
Show less packages

CVE-2024-29018

Medium priority

Some fixes available 5 of 8

Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distributions of container tooling or runtimes. Moby's networking implementation allows for many networks, each with...

2 affected packages

docker.io, docker.io-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
docker.io Ignored Ignored Ignored Fixed
docker.io-app Fixed Fixed Fixed
Show less packages