Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY19 SECURITY RECORDS

moby

moby

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at moby, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-42306 12 Jun 2026 github.com/docker/docker/daemon <= 28.5.2; Docker Engine < 29.5.1; github.com/moby/moby/v2/daemon < 2.0.0-beta.14 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 Update reference ↗
CVE-2026-41568 12 Jun 2026 github.com/docker/docker/daemon <= 28.5.2; Docker Engine < 29.5.1; github.com/moby/moby/v2/daemon < 2.0.0-beta.14 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-33997 31 Mar 2026 moby: < 29.3.1 RHSA-2026:22347: Multicluster Global Hub 1.4.5 Update reference ↗
CVE-2026-34040 31 Mar 2026 < 29.3.1 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation: https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/multicluster_global_hub/index Update reference ↗
CVE-2025-54410 30 Jul 2025 <= 25.0.12 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_openshift_data_foundation/4.22/html/updating_openshift_data_foundation/updating-ocs-to-odf_rhodf Update reference ↗
CVE-2025-54388 30 Jul 2025 >= 28.2.0, < 28.3.3 28.3.3. Update reference ↗
CVE-2024-41110 24 Jul 2024 >= 19.03.0, <= 19.03.15; >= 20.0.0, <= 20.10.27; >= 23.0.0, <= 23.0.14; >= 24.0.0, <= 24.0.9; >= 25.0.0, <= 25.0.5; >= 26.0.0, <= 26.0.2; >= 26.1.0, <= 26.1.14; >= 27.0.0, <= 27.0.3 Before applying this update, make sure all previously released errata relevant to your system have been applied. The steps to apply the upgraded images are different depending on the installation plan approval policy you used when installing the cert-manager Operator for Red Hat OpenShift. - If the approval policy is set to `Automatic`, then the Operator will be upgraded automatically when there is a new version of the Operator. No further action is required to upgrade. This is the default setting. - If you changed the approval policy to `Manual`, then you must manually approve the upgrade to the Operator. See https://docs.openshift.com/container-platform/latest/security/cert_manager_operator/index.html for additional information. Update reference ↗
CVE-2024-32473 18 Apr 2024 >= 26.0.0, < 26.0.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2024-29018 20 Mar 2024 >= 26.0.0-rc1, < 26.0.0-rc3; >= 25.0.0, < 25.0.5; < 23.0.11 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Update reference ↗
CVE-2024-24557 1 Feb 2024 >= 25.0.0, < 25.0.2; < 24.0.9 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 For supported configurations, refer to: https://access.redhat.com/articles/1548993 Update reference ↗
CVE-2023-28840 4 Apr 2023 >= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3 For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce Update reference ↗
CVE-2023-28841 4 Apr 2023 >= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3 For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce Update reference ↗
CVE-2023-28842 4 Apr 2023 >= 1.12.0, < 20.10.24; >= 23.0.0, < 23.0.3 For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.9/html/clusters/cluster_mce_overview#installing-while-connected-online-mce Update reference ↗
CVE-2022-36109 9 Sep 2022 < 20.10.18 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-24769 24 Mar 2022 < 20.10.14 For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.10/release_notes/ocp-4-10-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.10/updating/updating-cluster-cli.html Update reference ↗
CVE-2021-41089 4 Oct 2021 < 20.10.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-41091 4 Oct 2021 < 20.10.9 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-21284 2 Feb 2021 < 19.03.15; >= 20.0.0, < 20.10.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2021-21285 2 Feb 2021 < 19.03.15; >= 20.0.0, < 20.10.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.