FixVibe

high

Authorization Plugin Bypass in Moby (CVE-2026-34040)

Moby/Docker Engine versions before 29.3.1 include an AuthZ plugin bypass fixed in 29.3.1. The issue matters for deployments that rely on authorization plugins, especially policies that inspect request bodies. FixVibe GitHub repo scans flag affected Moby Go dependencies.

CVE-2026-34040GHSA-x744-4wpc-v9h2GHSA-x744-4wpc-v9h2CWE-288

Impact

Moby/Docker Engine versions before 29.3.1 include an authorization-plugin bypass tracked as CVE-2026-34040 / GHSA-x744-4wpc-v9h2 [S1][S2]. The advisory matters for deployments that use AuthZ plugins, especially policies that depend on request-body inspection; deployments that do not use AuthZ plugins are not affected by this issue [S1].

Root Cause

At a high level, the issue is an authorization-boundary problem in how request data is handled for AuthZ plugin decisions. The fix shipped in Moby 29.3.1, and the Go module advisory also lists fixed versions for github.com/docker/docker, github.com/moby/moby, and github.com/moby/moby/v2 [S1][S4].

Remediation

Upgrade Docker Engine/Moby to 29.3.1 or later. For Go module dependencies, move github.com/docker/docker and github.com/moby/moby to 29.3.1 or newer, and github.com/moby/moby/v2 to 2.0.0-beta.8 or newer [S1][S3]. Regenerate lock metadata, rebuild affected artifacts, and keep Docker API access restricted to trusted administrative paths.

Covered by FixVibe

FixVibe's GitHub repo scans flag Go projects that depend on affected versions of github.com/docker/docker, github.com/moby/moby, or github.com/moby/moby/v2.

Authorization Plugin Bypass in Moby (CVE-2026-34040)