moby v25.0.18

Moby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.

Image: Docker Blog

Why it matters

A flaw that allows crafted archives to write outside an extraction directory poses a security risk to Moby users. The release supplies a fix for the identified vulnerability.

Coverage 1 publisher

  1. Docker Blog

    moby v25.0.18

Articles stay on their publishers’ sites; each link opens the original.