CVE-2026-34040
CVSS 8.8 HIGH: moby is an open source container framework. EPSS 0.2% (5º percentile).
Vulnerabilità ed exploit
CVE-2026-34040 di Docker Engine è un bypass di autorizzazione ad alta gravità che infrange l'assunzione che i plugin di autorizzazione vedano l'intero corpo della richiesta API. Questa vulnerabilità consente agli attaccanti di inviare richieste API con padding che omettono il corpo della richiesta dalla vista del plugin, permettendo azioni non autorizzate che possono portare alla compromissione dell'host. La vulnerabilità è una regressione e una correzione incompleta per CVE-2024-41110, dimostrando che le patch precedenti non hanno affrontato completamente il problema sottostante.
2 fonti · 10 apr
CVSS 8.8 HIGH: moby is an open source container framework. EPSS 0.2% (5º percentile).
CSO Online
Old Docker authorization bypass pops up despite previous patch
A 10-year-old issue involving Docker Engine and the AuthZ authorization plug-in lives again to enable attackers to gain root-level access to host systems.
originaleThe Hacker News
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
Docker CVE-2026-34040 enables AuthZ bypass via padded requests, risking host compromise; fixed in version 29.3.1.
originalePart of the PlainSec briefing for 2026-04-11
Every edition of this story: Il bypass di Docker AuthZ riapre il rischio di compromissione dell'host