moby v25.0.18
Docker BlogMoby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.
Publisher
Stories with reporting from Docker Blog, ranked by what is gaining ground now. Each story links to the original articles.
Docker BlogMoby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.
Docker BlogMoby v29.8.2 fixes a Docker Engine security vulnerability involving crafted OCI image indexes with deeply nested or widely fanned-out structures. The release note identifies the issue as CVE-2026-53493.
Docker BlogMoby 25.0.17 fixes CVE-2026-41568, a symlink escape in mount destination creation, and adds archive decompression before data enters a container. The release includes changes to the Engine API as well as other fixes and enhancements.
Docker BlogMoby 29.6.2 includes fixes for multiple security vulnerabilities affecting Docker Engine. One listed issue, CVE-2026-15793, involves Git source checkout from a bundle file that could lead to command execution.
Docker BlogMoby 29.6.1 includes fixes for multiple security vulnerabilities affecting Docker Engine. One issue involves a malicious image supplying a malicious /etc/passwd- or /etc/group-style file.
Docker BlogMoby 29.5.1 includes fixes for multiple security vulnerabilities affecting Docker Engine. One fix addresses CVE-2026-41567, a vulnerability in `docker cp` involving archive decompression.
Docker BlogMoby API v1.55.0 adds per-device block I/O resource settings to the container-update endpoint. It also adds an image-attestations endpoint that can return in-toto statements, including SLSA provenance and SPDX SBOMs, with filtering and optional retrieval of statement bodies.
Docker BlogMoby 29.5.0 makes `gvisor-tap-vsock` the default rootless network driver and removes `slirp4netns` from Docker packaging. The release notes say `gvisor-tap-vsock` should be preferred for rootless networking.
Docker BlogDocker is bringing its open-source Sandbox Kit Spec to the CNCF to establish a vendor-independent standard for AI agent permissions built on OCI.
Docker BlogMoby 29.7.0 adds an experimental `embedded-containerd` feature that runs containerd inside the daemon process rather than as a separately managed process. The change concerns Docker daemon architecture and is marked experimental.
Docker BlogMoby 29.8.0 adds a `HostConfig.Umask` option and a `--umask` flag to `docker create` and `docker run`. The setting controls the umask for a container’s main process, execs, and healthchecks.
Docker BlogDocker presents Cloud Sandboxes and the open Sandbox Kit specification, and commits to bringing Kits to the CNCF for neutral governance. The announcements concern safe environments for running coding agents and an open framework for those environments.
Docker BlogDocker introduces Cloud Sandboxes, allowing coding agents to run on a laptop or in the cloud and move between the environments with one command. The product extends Docker Sandboxes, microVM environments designed for autonomous agent work.
Docker BlogDocker’s Sandbox Kit Specification v3 packages an AI agent’s network rules, credentials, and volumes as an OCI image. The image can be pinned, making the sandbox configuration portable and reproducible.
Docker BlogMoby client 0.5.0 adds a GET /images/{name}/attestations endpoint for retrieving in-toto attestation statements attached to an image. It supports platform selection and predicate filtering, and can return verbatim statement bodies with an optional query parameter.
Docker BlogMoby 29.7.1 fixes a regression that prevented users from pulling images when their layers contain directories without explicit parent-directory entries.
Docker BlogMoby client 0.6.1 adds a `WithHTTPRequestHook` option, deprecates `WithResponseHook` in favor of `WithHTTPResponseHook`, and fixes response hooks not being called for hijacked HTTP connections. It also updates `postRaw` to use a consistent argument order.
Docker BlogMoby 29.6.0 adds per-device block I/O resource settings to the container update API and adds an image attestations endpoint. The release notes also point to Docker CLI and Moby milestones for the full change lists.
Docker BlogMoby 29.7.2 fixes a panic in docker service create and docker service update when the same environment variable is supplied more than once.
Docker BlogMoby API 1.56.0 adds an annotation filter to `GET /containers/json`, supporting filtering by key or key and value. `POST /containers/create` also gains `HostConfig.Umask` support, which sets the Unix container's initial umask in its OCI process configuration.