github.com/moby/moby
Ecosystem:
go
go
Package URL:
pkg:golang/github.com/moby/moby
Total PRs:
167 Dependabot PRs
167 Dependabot PRs
Latest PR:
3 months ago
3 months ago
Unique Repositories:
40 repositories
40 repositories
Unique Repos (30 days):
1 repository
1 repository
Security Advisories
Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap
GHSA-vp62-88p7-qqf5
CVE-2026-41568
MODERATE
published 22 days ago
• updated 10 days ago
## Summary
A race condition during `docker cp` mount setup allows a malicious container to create empty files or directories at arbitrary absolute...
moby Access to remapped root allows privilege escalation to real root
GHSA-7452-xqpj-6rpc
CVE-2021-21284
MODERATE
published over 2 years ago
• updated about 1 month ago
### Impact
When using `--userns-remap`, if the root user in the remapped namespace has access to the host filesystem they can modify files under `...
Moby Race Condition vulnerability
GHSA-2mj3-vfvx-fc43
CVE-2024-36621
HIGH
published over 1 year ago
• updated 16 days ago
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurr...
Moby (Docker Engine) Insufficiently restricted permissions on data directory
GHSA-3fwx-pjgw-3558
CVE-2021-41091
MODERATE
published over 2 years ago
• updated about 1 hour ago
## Impact
A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficien...
Moby (Docker Engine) started with non-empty inheritable Linux process capabilities
GHSA-2mm7-x5h6-5pvq
CVE-2022-24769
MODERATE
published about 2 years ago
• updated 8 days ago
### Impact
A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities...
Recent PRs (filtered by: Closed , Patch PRs )
Bump the docker group across 1 directory with 4 updates
dependabot/cli #553
28.5.1+incompatible → 28.5.2+incompatible
Patch PR
Closed
6 months ago
1 comment
Bump the docker group with 2 updates
dependabot/cli #488
28.3.2+incompatible → 28.3.3+incompatible
Patch PR
Closed
10 months ago
1 comment
go: bump github.com/moby/moby from 28.3.0+incompatible to 28.3.2+incompatible in the docker group across 1 directory
inspektor-gadget/ig-desktop #233
28.3.0+incompatible → 28.3.2+incompatible
Patch PR
Closed
11 months ago
1 comment
Bump the docker group with 3 updates
dependabot/cli #480
28.3.0+incompatible → 28.3.2+incompatible
Patch PR
Closed
11 months ago
1 comment
Bump the all group across 1 directory with 8 updates
dependabot/cli #477
28.3.0+incompatible → 28.3.1+incompatible
Patch PR
Closed
11 months ago
1 comment
Package Details
| Name: | github.com/moby/moby |
| Ecosystem: | go |
| PURL Type: | golang |
| Package URL: | pkg:golang/github.com/moby/moby |
| JSON API: | View JSON |
Security Advisories
Package Information
Description:
| Repository: | https://github.com/moby/moby |
| Homepage: | https://github.com/moby/moby |
| Latest Release: |
v27.3.1+incompatible
over 1 year ago |
| Dependent Repos: | 1,657 |
| Dependent Packages: | 461 |
| Ranking: | Top 0.1951% by dependent repos Top 0.1978% by dependent pkgs |