Package
manifest-tool
Component
github.com/docker/docker
Latest update
8.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
Fix for this CVE is available in Docker Engine v29.3.1 and github.com/moby/moby/v2 v2.0.0-beta.8. A fix has also been committed to the moby/moby 28.x branch (https://github.com/moby/moby/commit/6d311e0d8d4174a6347942db78c553fb7dc3762e) but no release has been tagged yet. The github.com/docker/docker module that manifest-tool vendors tops out at v28.5.2+incompatible with no backport available, so the fix cannot be applied. Awaiting upstream maintainer action.
Status