Moby 25.0.17 fixes CVE-2026-41568, a symlink escape in mount destination creation, and adds archive decompression before data enters a container. The release includes changes to the Engine API as well as other fixes and enhancements.
1 sourcePublished Updated
Why it matters
The release addresses a container mount-path security flaw in Moby. Operators using this version should review the fix when planning updates.