CVE-2026-34040

NameCVE-2026-34040
DescriptionMoby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
docker.io (PTS)bullseye20.10.5+dfsg1-1+deb11u2vulnerable
bullseye (security)20.10.5+dfsg1-1+deb11u4vulnerable
bookworm20.10.24+dfsg1-1+deb12u1vulnerable
trixie26.1.5+dfsg1-9vulnerable
forky, sid28.5.2+dfsg3-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
docker.iosource(unstable)(unfixed)

Notes

[trixie] - docker.io <no-dsa> (Minor issue)
[bookworm] - docker.io <no-dsa> (Minor issue)
https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2
https://github.com/moby/moby/commit/6d311e0d8d4174a6347942db78c553fb7dc3762e (28.x)
https://github.com/moby/moby/commit/db7dadaca041953430d1e2144088c311b78b96d7 (28.x)

Search for package or bug name: Reporting problems