Docker Moby <29.5.1: Decompression Binary Hijack in /containers/{id}/archive
CVE-2026-41567 Published on June 5, 2026

Docker: `PUT /containers/{id}/archive` executes container binary on the host
Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

NVD

Vulnerability Analysis

CVE-2026-41567 can be exploited with local system access, requires user interaction and a small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.

Attack Vector:
LOCAL
Attack Complexity:
HIGH
Privileges Required:
LOW
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH

Weakness Type

What is a DLL preloading Vulnerability?

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

CVE-2026-41567 has been classified to as a DLL preloading vulnerability or weakness.


Products Associated with CVE-2026-41567

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-41567 are published in these products:

 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

moby/v2/daemon: moby Docker Engine: docker/daemon: Red Hat Multicluster Global Hub 1.4.5: Red Hat Multicluster Global Hub 1.5.6: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Openshift Data Foundation 4.22: Red Hat Exploit Intelligence: Red Hat Multicluster Engine for Kubernetes: Red Hat Multicluster Engine for Kubernetes: Red Hat Multicluster Engine for Kubernetes: Red Hat OpenShift Lightspeed: Red Hat OpenShift Source-to-Image (S2I): Red Hat OpenShift Source-to-Image (S2I): Red Hat Advanced Cluster Management for Kubernetes 2: Red Hat Ceph Storage 5: Red Hat Ceph Storage 7: Red Hat Ceph Storage 8: Red Hat Ceph Storage 9: Red Hat Enterprise Linux 10: Red Hat Enterprise Linux 9: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift distributed tracing 3:

Exploit Probability

EPSS
0.14%
Percentile
3.43%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.