—
GO-2026-4887
Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker
Quick fix
GO-2026-4887 — github.com/moby/moby/v2: upgrade to the fixed version with the command below.
go get github.com/moby/moby/v2@v2.0.0-beta.8 Details
Moby has AuthZ plugin bypass when provided oversized request bodies in github.com/docker/docker
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/docker/docker
Introduced in:
0 No fixed version published yet for github.com/docker/docker (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/moby/moby
Introduced in:
0 No fixed version published yet for github.com/moby/moby (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/moby/moby/v2
Introduced in:
0 Fixed in: 2.0.0-beta.8 Fix
go get github.com/moby/moby/v2@v2.0.0-beta.8 References
- https://github.com/moby/moby/security/advisories/GHSA-x744-4wpc-v9h2 [ADVISORY]
- https://github.com/moby/moby/commit/e89edb19ad7de0407a5d31e3111cb01aa10b5a38 [FIX]
- https://docs.docker.com/engine/extend/plugins_authorization [WEB]
- https://github.com/moby/moby/security/advisories/GHSA-v23v-6jw2-98fq [WEB]