Package
datadog-agent-fips-7.83
Component
github.com/docker/docker
Latest update
8.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-34040 (GHSA-x744-4wpc-v9h2) is an AuthZ plugin bypass in Moby, fixed upstream in moby/moby release docker-v29.3.1 by rejecting request bodies over 4 MiB before forwarding them to authorization plugins. The pinned github.com/docker/docker pseudo-version (v28.5.3-...-31a1689cb0a1) already contains that exact body-size check, backported ahead of an official tag (the pinned commit's own message is pkg/authz: Reject requests with body size exceeding 4 MiB). The pseudo-version string sorts below 29.3.1 and over-matches the CVE's affected range, but the vulnerable code path is not present in the code actually shipped.
Status