Impact
Moby/Docker Engine versions before 29.3.1 include an authorization-plugin bypass tracked as CVE-2026-34040 / GHSA-x744-4wpc-v9h2 [S1][S2]. The advisory matters for deployments that use AuthZ plugins, especially policies that depend on request-body inspection; deployments that do not use AuthZ plugins are not affected by this issue [S1].
Root Cause
At a high level, the issue is an authorization-boundary problem in how request data is handled for AuthZ plugin decisions. The fix shipped in Moby 29.3.1, and the Go module advisory also lists fixed versions for github.com/docker/docker, github.com/moby/moby, and github.com/moby/moby/v2 [S1][S4].
Remediation
Upgrade Docker Engine/Moby to 29.3.1 or later. For Go module dependencies, move github.com/docker/docker and github.com/moby/moby to 29.3.1 or newer, and github.com/moby/moby/v2 to 2.0.0-beta.8 or newer [S1][S3]. Regenerate lock metadata, rebuild affected artifacts, and keep Docker API access restricted to trusted administrative paths.
Covered by FixVibe
FixVibe's GitHub repo scans flag Go projects that depend on affected versions of github.com/docker/docker, github.com/moby/moby, or github.com/moby/moby/v2.
