Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x744-4wpc-v9h2 | Moby has AuthZ plugin bypass when provided oversized request bodies |
Mon, 06 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 03 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobyproject
Mobyproject moby |
|
| CPEs | cpe:2.3:a:mobyproject:moby:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mobyproject
Mobyproject moby |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby moby |
|
| Vendors & Products |
Moby
Moby moby |
Tue, 31 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1. | |
| Title | Moby: AuthZ plugin bypass with oversized request body | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-02T03:55:56.676Z
Reserved: 2026-03-25T15:29:04.744Z
Link: CVE-2026-34040
Updated: 2026-03-31T15:34:59.017Z
Status : Analyzed
Published: 2026-03-31T03:15:57.883
Modified: 2026-04-03T16:51:28.670
Link: CVE-2026-34040
OpenCVE Enrichment
Updated: 2026-04-07T08:08:14Z
Github GHSA