Moby: AuthZ plugin bypass with oversized request body
Published Mar 31, 2026
8.8
HIGHCVSS 3.1
EPSS 0.16%
Description
Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.
Affected products
-
- Version < 29.3.1StatusaffectedConstraints-
- Version
No data.
Multicluster Global Hub 1.4.9
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439
Fixed · RHSA-2026:22347
Multicluster Global Hub 1.4.9
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788375682
Fixed · RHSA-2026:67516
Multicluster Global Hub 1.6.5
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118
Fixed · RHSA-2026:23345
Multicluster Global Hub 1.7.3
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273
Fixed · RHSA-2026:24503
Multicluster Global Hub 1.7.3
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788376193
Fixed · RHSA-2026:67842
Red Hat multicluster global hub 1.5.3
multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753
Fixed · RHSA-2026:21769
Multicluster Engine for Kubernetes
multicluster-engine/assisted-installer-agent-rhel9
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-installer-controller-rhel9
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-installer-rhel9
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-8-rhel8
Affected
Multicluster Engine for Kubernetes
multicluster-engine/assisted-service-9-rhel9
Affected
Multicluster Engine for Kubernetes
multicluster-engine/must-gather-rhel9
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/istio-rhel8-operator
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-must-gather-rhel9
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/prometheus-rhel9
Not affected
Red Hat Ceph Storage 5
rhceph-ci/grafana
Affected
Red Hat OpenShift Container Platform 4
openshift3/ose-console
Affected
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-api-server-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-agent-installer-api-server-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
Red Hat OpenShift Virtualization 4
openshift-virtualization/hostpath-csi-driver-rhel9
Not affected
Red Hat OpenShift Virtualization 4
openshift-virtualization/hostpath-provisioner-operator-rhel9
Not affected
Red Hat OpenShift Virtualization 4
openshift-virtualization/hostpath-provisioner-rhel9
Not affected
Red Hat OpenShift Virtualization 4
openshift-virtualization/hyperconverged-cluster-operator-rhel9
Not affected
Red Hat OpenShift Virtualization 4
openshift-virtualization/hyperconverged-cluster-webhook-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Multicluster Global Hub 1.4.9 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779579439 | Fixed | RHSA-2026:22347 |
| Multicluster Global Hub 1.4.9 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788375682 | Fixed | RHSA-2026:67516 |
| Multicluster Global Hub 1.6.5 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1780167118 | Fixed | RHSA-2026:23345 |
| Multicluster Global Hub 1.7.3 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273 | Fixed | RHSA-2026:24503 |
| Multicluster Global Hub 1.7.3 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788376193 | Fixed | RHSA-2026:67842 |
| Red Hat multicluster global hub 1.5.3 | multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1778867753 | Fixed | RHSA-2026:21769 |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-installer-agent-rhel9 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-installer-controller-rhel9 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-installer-rhel9 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-8-rhel8 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-service-9-rhel9 | Affected | n/a |
| Multicluster Engine for Kubernetes | multicluster-engine/must-gather-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/istio-rhel8-operator | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-must-gather-rhel9 | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/prometheus-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph-ci/grafana | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift3/ose-console | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-api-server-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-agent-installer-api-server-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-virtualization/hostpath-csi-driver-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-virtualization/hostpath-provisioner-operator-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-virtualization/hostpath-provisioner-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-virtualization/hyperconverged-cluster-operator-rhel9 | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | openshift-virtualization/hyperconverged-cluster-webhook-rhel9 | Not affected | n/a |
github.com/moby/moby/v2
Go
Introduced 0 Fixed 2.0.0-beta.8github.com/docker/docker
Go
Introduced 0 Fixed not fixedgithub.com/moby/moby
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/moby/moby/v2 | 0 | 2.0.0-beta.8 |
| Go | github.com/docker/docker | 0 | not fixed |
| Go | github.com/moby/moby | 0 | not fixed |
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 31, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Mar–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.16% (0.00163) | 4.95th | v5 (v2026.06.15) |
| Aug 27, 2026 | 9.11% (0.09113) | 94.92th | v5 (v2026.06.15) |
| Jul 24, 2026 | 10.14% (0.10140) | 95.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 8.12% (0.08123) | 94.09th | v5 (v2026.06.15) |
| Mar 31, 2026 | 0.01% (0.00012) | 1.62th | v4 (v2025.03.14) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-34040 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2453278 Issue Tracking
- https://docs.docker.com/engine/extend/plugins_authorization
- https://github.com/advisories/GHSA-x744-4wpc-v9h2 Advisory
- https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38
- https://github.com/moby/moby/releases/tag/docker-v29.3.1 x_refsource_MISCRelease Notes
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34040
- https://www.cve.org/CVERecord?id=CVE-2026-34040
Change history (0)
No recorded changes yet.