{"api_version":"v1","generated_at":"2026-10-06T10:25:00+00:00","product":{"cve_count":19,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-moby-moby-8a07ed5e6dcb","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/moby","name":"moby","next_cursor":null,"observations":[{"affected":"github.com/docker/docker/daemon <= 28.5.2; Docker Engine < 29.5.1; github.com/moby/moby/v2/daemon < 2.0.0-beta.14","affected_versions_present":true,"cve_id":"CVE-2026-42306","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42306","fixed":"See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1","last_modified":"2026-06-13T03:25:47.055Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-42306","primary_source":"","published":"2026-06-12T18:09:22.188Z"},{"affected":"github.com/docker/docker/daemon <= 28.5.2; Docker Engine < 29.5.1; github.com/moby/moby/v2/daemon < 2.0.0-beta.14","affected_versions_present":true,"cve_id":"CVE-2026-41568","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41568","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-12T20:01:58.963Z","patch_url":"https://github.com/moby/moby/security/advisories/GHSA-vp62-88p7-qqf5","primary_source":"","published":"2026-06-12T18:08:43.914Z"},{"affected":"moby: < 29.3.1","affected_versions_present":true,"cve_id":"CVE-2026-33997","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33997","fixed":"RHSA-2026:22347: Multicluster Global Hub 1.4.5","last_modified":"2026-09-09T12:04:48.189Z","patch_url":"https://github.com/moby/moby/security/advisories/GHSA-pxq6-2prw-chj9","primary_source":"","published":"2026-03-31T01:36:51.404Z"},{"affected":"< 29.3.1","affected_versions_present":true,"cve_id":"CVE-2026-34040","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34040","fixed":"For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index","last_modified":"2026-04-02T03:55:56.676Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-34040","primary_source":"","published":"2026-03-31T01:36:48.205Z"},{"affected":"<= 25.0.12","affected_versions_present":true,"cve_id":"CVE-2025-54410","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54410","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf","last_modified":"2025-07-30T13:38:40.357Z","patch_url":"https://access.redhat.com/security/cve/CVE-2025-54410","primary_source":"","published":"2025-07-30T13:24:50.818Z"},{"affected":">= 28.2.0, < 28.3.3","affected_versions_present":true,"cve_id":"CVE-2025-54388","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54388","fixed":"28.3.3.","last_modified":"2025-07-30T13:38:07.559Z","patch_url":"https://github.com/moby/moby/pull/50506","primary_source":"","published":"2025-07-30T13:24:06.849Z"},{"affected":">= 19.03.0, <= 19.03.15; >= 20.0.0, <= 20.10.27; >= 23.0.0, <= 23.0.14; >= 24.0.0, <= 24.0.9; >= 25.0.0, <= 25.0.5; >= 26.0.0, <= 26.0.2; >= 26.1.0, <= 26.1.14; >= 27.0.0, <= 27.0.3","affected_versions_present":true,"cve_id":"CVE-2024-41110","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-41110","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information.","last_modified":"2024-10-13T21:03:34.392Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-41110","primary_source":"","published":"2024-07-24T16:49:53.068Z"},{"affected":">= 26.0.0, < 26.0.2","affected_versions_present":true,"cve_id":"CVE-2024-32473","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32473","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-21T14:21:22.127Z","patch_url":"https://github.com/moby/moby/commit/7cef0d9cd1cf221d8c0b7b7aeda69552649e0642","primary_source":"","published":"2024-04-18T21:55:50.445Z"},{"affected":">= 26.0.0-rc1, < 26.0.0-rc3; >= 25.0.0, < 25.0.5; < 23.0.11","affected_versions_present":true,"cve_id":"CVE-2024-29018","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-29018","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2024-08-13T17:00:25.512Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-29018","primary_source":"","published":"2024-03-20T20:27:00.491Z"},{"affected":">= 25.0.0, < 25.0.2; < 24.0.9","affected_versions_present":true,"cve_id":"CVE-2024-24557","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-24557","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 For supported configurations, refer to: https://access.redhat.com/articles/1548993","last_modified":"2025-05-15T15:27:27.082Z","patch_url":"https://access.redhat.com/security/cve/CVE-2024-24557","primary_source":"","published":"2024-02-01T16:26:29.685Z"},{"affected":">= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3","affected_versions_present":true,"cve_id":"CVE-2023-28840","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28840","fixed":"For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce","last_modified":"2025-02-13T16:48:53.710Z","patch_url":"https://access.redhat.com/security/cve/CVE-2023-28840","primary_source":"","published":"2023-04-04T21:13:03.347Z"},{"affected":">= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3","affected_versions_present":true,"cve_id":"CVE-2023-28841","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28841","fixed":"For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce","last_modified":"2025-02-13T16:48:54.707Z","patch_url":"https://access.redhat.com/security/cve/CVE-2023-28841","primary_source":"","published":"2023-04-04T21:12:17.406Z"},{"affected":">= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3","affected_versions_present":true,"cve_id":"CVE-2023-28842","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28842","fixed":"For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce","last_modified":"2025-02-13T16:48:55.735Z","patch_url":"https://access.redhat.com/security/cve/CVE-2023-28842","primary_source":"","published":"2023-04-04T21:07:27.575Z"},{"affected":"< 20.10.18","affected_versions_present":true,"cve_id":"CVE-2022-36109","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-36109","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:12:31.122Z","patch_url":"https://github.com/moby/moby/commit/de7af816e76a7fd3fbf06bffa6832959289fba32","primary_source":"","published":"2022-09-09T17:20:11.000Z"},{"affected":"< 20.10.14","affected_versions_present":true,"cve_id":"CVE-2022-24769","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24769","fixed":"For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html","last_modified":"2024-08-03T04:20:49.949Z","patch_url":"https://access.redhat.com/security/cve/CVE-2022-24769","primary_source":"","published":"2022-03-24T00:00:00.000Z"},{"affected":"< 20.10.9","affected_versions_present":true,"cve_id":"CVE-2021-41089","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41089","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.512Z","patch_url":"https://github.com/moby/moby/commit/bce32e5c93be4caf1a592582155b9cb837fc129a","primary_source":"","published":"2021-10-04T20:20:15.000Z"},{"affected":"< 20.10.9","affected_versions_present":true,"cve_id":"CVE-2021-41091","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41091","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.575Z","patch_url":"https://github.com/moby/moby/commit/f0ab919f518c47240ea0e72d0999576bb8008e64","primary_source":"","published":"2021-10-04T20:20:09.000Z"},{"affected":"< 19.03.15; >= 20.0.0, < 20.10.3","affected_versions_present":true,"cve_id":"CVE-2021-21284","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21284","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.042Z","patch_url":"https://docs.docker.com/engine/release-notes/#20103","primary_source":"","published":"2021-02-02T17:55:22.000Z"},{"affected":"< 19.03.15; >= 20.0.0, < 20.10.3","affected_versions_present":true,"cve_id":"CVE-2021-21285","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21285","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.012Z","patch_url":"https://docs.docker.com/engine/release-notes/#20103","primary_source":"","published":"2021-02-02T17:55:16.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"moby"}}
