moby v25.0.17
Moby 25.0.17 fixes CVE-2026-41568, a symlink escape in mount destination creation, and adds archive decompression before data enters a container. The release includes changes to the Engine API as well as other fixes and enhancements.
Vulnerability
Every story that mentions CVE-2026-41567, newest first.
Moby 25.0.17 fixes CVE-2026-41568, a symlink escape in mount destination creation, and adds archive decompression before data enters a container. The release includes changes to the Engine API as well as other fixes and enhancements.
Moby 29.5.1 includes fixes for multiple security vulnerabilities affecting Docker Engine. One fix addresses CVE-2026-41567, a vulnerability in `docker cp` involving archive decompression.