CVE-2026-34040

Severity
7.8HIGH
EPSS
0.0%
top 97.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 7

Description

Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages3 packages

CVEListV5moby/moby< 29.3.1
NVDmobyproject/moby< 29.3.1
Gogithub.com/moby/moby/v2< 2.0.0-beta.8

🔴Vulnerability Details

5
OSV
Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker2026-04-02
OSV
CVE-2026-34040: Moby is an open source container framework2026-03-31
CVEList
Moby: AuthZ plugin bypass with oversized request body2026-03-31
OSV
Moby has AuthZ plugin bypass when provided oversized request bodies2026-03-27
GHSA
Moby has AuthZ plugin bypass when provided oversized request bodies2026-03-27

📋Vendor Advisories

2
Red Hat
Moby: Moby: Authorization bypass vulnerability2026-03-31
Debian
CVE-2026-34040: docker.io - Moby is an open source container framework. Prior to version 29.3.1, a security ...2026

🕵️Threat Intelligence

2
Hackernews
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access2026-04-07
Wiz
CVE-2026-34040 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

4
Bugzilla
CVE-2026-34040 golang-github-docker: Moby: Authorization bypass vulnerability [fedora-42]2026-04-06
Bugzilla
CVE-2026-34040 inspektor-gadget: Moby: Authorization bypass vulnerability [fedora-42]2026-04-06
Bugzilla
CVE-2026-34040 inspektor-gadget: Moby: Authorization bypass vulnerability [fedora-43]2026-04-06
Bugzilla
CVE-2026-34040 Moby: Moby: Authorization bypass vulnerability2026-03-31
CVE-2026-34040 (HIGH CVSS 7.8) | Moby is an open source container fr | cvebase.io