
🚨 High - Moby/Docker Container Escape Race Condition (CVE-2026-42306) A Time-of-Check to Time-of-Use (TOCTOU) race condition during docker cp operations allows a malicious container to redirect a bind mount to an arbitrary host path. By rapidly replacing the volume mount destination with a symlink before the mount() syscall executes, an attacker can overwrite critical files on the host system or mask host paths to cause a denial of service. 👉 Affected: http://github. com/docker/docker (<= 28.5.2), http://github. com/moby/moby (<= 28.5.2), http://github. com/moby/moby/v2 (< 2.0.0-beta.14) | Upgrade to moby/moby/v2 >= 2.0.0-beta.14
Post summary
A new container escape vulnerability (CVE-2026-42306) allows Docker containers to overwrite host files via a symlink race during docker cp. The issue is mitigated by upgrading to moby/moby/v2 version 2.0.0-beta.14 or later.

