moby v25.0.18
Moby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.
Vulnerability
Every story that mentions CVE-2026-17106, newest first.
Moby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.
Moby 29.7.0 adds an experimental `embedded-containerd` feature that runs containerd inside the daemon process rather than as a separately managed process. The change concerns Docker daemon architecture and is marked experimental.