Repository navigation
Releases: moby/moby
Release list
v29.9.0
29.9.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
The Go runtime update fixes the following security vulnerabilities in Docker Engine:
- CVE-2026-97032: An HTTP/2 client could crash the daemon by changing the HPACK header table size while sending requests. golang/go#81867
- CVE-2026-78659: An HTTP/2 client could exhaust daemon memory by declaring a large number of fields in a
Trailerheader, bypassing the header size limits. golang/go#81857 - CVE-2026-78663: An HTTP/2 client could bypass the connection-level flow control limit by resetting streams, making the daemon buffer more request data than the limit allows. golang/go#81743
- CVE-2026-78669: An HTTP/2 client could cause excessive daemon CPU use by opening many streams and repeatedly changing the initial window size. golang/go#81742
- CVE-2026-56857: On Windows, the daemon could create a directory outside its data root if someone with write access to the data root had placed a junction there. golang/go#81739
The golang.org/x/net update to v0.60.0 applies the same HTTP/2 fixes to the deprecated /grpc endpoint and to the gRPC server that BuildKit runs for frontend containers, such as images referenced by a # syntax= directive.
Bug fixes and enhancements
- containerd image store: Add the
lazy-pulldaemon feature to control whetherdocker pullskips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (nydus,overlaybd,soci,stargz). moby/moby#53877 - containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. moby/moby#53615
- Fix
docker container create --namereporting a misleading validation error mentioning invalid characters instead of invalid name length. moby/moby#53484 - Fix a connection leak to the RootlessKit API socket on every
GET /versionrequest in rootless mode. moby/moby#53836 - Improve Windows service registration and unregistration cleanup, including making service unregistration (
--unregister-service) idempotent. moby/moby#53845
Packaging updates
- Update BuildKit to v0.34.0. moby/moby#53882
- Update Go runtime to 1.26.9. docker/cli#7363
- Update containerd (static binaries) to v2.4.1. moby/moby#53773
Networking
- Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. moby/moby#53723
- Fix
docker psandGET /containers/jsonomitting published ports for networks using routed gateway mode. moby/moby#53693 - Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. moby/moby#53688
- Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. moby/moby#53723
- Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). moby/moby#53420
- Fix connecting live-restored containers with an implicit
host-gatewaymapping to additional networks. moby/moby#53093 - Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. moby/moby#53663
- Fix Swarm tasks on overlay networks being rejected when the daemon can't write to
/var/lib/docker. moby/moby#53848 - Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. moby/moby#53727
- Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. moby/moby#53420
- Restore the logic to remove the empty
DOCKER-INGRESSiptables chain, and theFORWARDrule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. moby/moby#53825
Rootless
- Update RootlessKit (3.2.0). moby/moby#53607
client/v0.6.2
0.6.2
Changelog
- client: bump github.com/docker/go-connections v0.8.2, github.com/Azure/go-ansiterm 8c912ac31dd4. moby/moby#53891
- Fix request cancellation and deadlines during client HTTP upgrade handshakes. moby/moby#53889
v29.9.0-rc.2
29.9.0-rc.2
For a full list of changes from the last release candidate refer to the diff:
Bug fixes and enhancements
- containerd image store: Add the
lazy-pulldaemon feature to control whetherdocker pullskips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (nydus,overlaybd,soci,stargz). moby/moby#53877 - containerd image store: Fix a regression in v29.9.0-rc.1 where
docker pulldownloaded all layer content when using a remote snapshotter such as stargz. moby/moby#53877 - Improve Windows service registration and unregistration cleanup, including making service unregistration (
--unregister-service) idempotent. moby/moby#53845
Packaging updates
- Update BuildKit to v0.34.0-rc2. moby/moby#53869
Networking
- Fix Swarm tasks on overlay networks being rejected when the daemon can't write to
/var/lib/docker. moby/moby#53848
client/v0.6.1
0.6.1
Changelog
- client: add
WithHTTPRequestHookoption. moby/moby#53671 - client: deprecate
WithResponseHookin favor ofWithHTTPResponseHook. moby/moby#53666 - client: fix
WithHTTPResponseHookhooks not being called for hijacked HTTP connections. moby/moby#53821 - client: postRaw: use consistent order or arguments. moby/moby#53677
- client: prevent response hooks from consuming response body. moby/moby#53667
- client: remove redundant cloning of response hooks. moby/moby#53822
- client: update github.com/docker/go-connections v0.8.1. moby/moby#53708
- golangci-lint: enable usetesting linter. moby/moby#53720
- vendor: github.com/moby/moby/api v1.56.1. moby/moby#53837
api/v1.56.1
1.56.1
Changelog
- api/scripts: Allow isolated model generation with an API directory. moby/moby#53629
- api/swagger: Improve OpenAPI compatibility. moby/moby#53626
- api/swagger: Quote HTTP response status codes. moby/moby#53759
- api/templates: schema: disable validators and serializer sections. moby/moby#53751
- api: fix G117 (gosec). moby/moby#53721
- api: swagger ImageManifestSummary.ImageData: fix invalid required field. moby/moby#53750
- api: update go-swagger to v0.36.6. moby/moby#53754
- fix: invalid swagger YAML indentation. moby/moby#53606
v29.9.0-rc.1
29.9.0-rc.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. moby/moby#53615
- Fix
docker container create --namereporting a misleading validation error mentioning invalid characters instead of invalid name length. moby/moby#53484 - Fix a connection leak to the RootlessKit API socket on every
GET /versionrequest in rootless mode. moby/moby#53836
Packaging updates
- Update BuildKit to v0.34.0-rc1. moby/moby#53830
- Update containerd (static binaries) to v2.4.1. moby/moby#53773
Networking
- Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. moby/moby#53723
- Fix
docker psandGET /containers/jsonomitting published ports for networks using routed gateway mode. moby/moby#53693 - Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. moby/moby#53688
- Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. moby/moby#53723
- Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). moby/moby#53420
- Fix connecting live-restored containers with an implicit
host-gatewaymapping to additional networks. moby/moby#53093 - Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. moby/moby#53663
- Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. moby/moby#53727
- Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. moby/moby#53420
- Restore the logic to remove the empty
DOCKER-INGRESSiptables chain, and theFORWARDrule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. moby/moby#53825
Rootless
- Update RootlessKit (3.2.0). moby/moby#53607
v25.0.18
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestone:
- moby/moby, 25.0.18 milestone
- Changes to the Engine API, see API version history.
Bug fixes and enhancements
- Fix CVE-2026-17106: crafted tar archive can write outside the extraction directory. #53470
v29.8.2
29.8.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release fixes the following security vulnerabilities in Docker Engine:
- CVE-2026-53493: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. GHSA-pg57-6jwg-q645
- CVE-2026-92543: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. GHSA-7cfq-22r6-qp73
- CVE-2026-92542: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. GHSA-6m9p-4h64-m6vh
The BuildKit update fixes the following security vulnerabilities:
- CVE-2026-93315: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. GHSA-2f5p-x9ph-g97x
- CVE-2026-93316: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with
"features": {"cdi": false}indaemon.json. GHSA-r456-g3gm-cvxf - CVE-2026-93317: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. GHSA-p3rc-w3hc-pqvv
- CVE-2026-93318: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. GHSA-f2v9-hprr-32q3
- CVE-2026-93319: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
- CVE-2026-93320: Daemon-side snapshot reads and LLB
mkfileoperations did not safely handle special files. GHSA-9728-qjrv-2xh2 - CVE-2026-93321: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. GHSA-fjj4-h6vf-m9hj
- CVE-2026-93322: A malformed LLB merge operation with mismatched input counts could crash the daemon. GHSA-cv6p-7w7g-xjwq
- CVE-2026-93323: An oversized Dockerfile,
.dockerignore, gateway file, or nested LLB definition could exhaust daemon memory. GHSA-mgqf-486f-49vp - CVE-2026-93326: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. GHSA-66hf-6vf5-87hc
Bug fixes and enhancements
- Fix
docker cpfailing on a container with a bind-mounted socket nested inside another bind mount. moby/moby#53724 - Fix
docker infofailing with an “invalid Prefix” error after reloading a daemon with custom default address pools. moby/moby#53812
Packaging updates
- Update BuildKit to v0.33.1. moby/moby#53823
- Update containerd (static binaries) to v2.3.6. moby/moby#53778
- Update runc (in static binaries) to v1.5.2. moby/moby#53811
v29.8.1
29.8.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- containerd image store: Fix
docker loadleaving dangling images after loading an image that already exists. moby/moby#53595 - Fix managed containerd logging a CRI pod-sandbox plugin dependency warning during startup. moby/moby#53585
- Fix user-namespace detection on OpenVZ, where namespace inode numbers are virtualized. moby/moby#53605
- Windows: Preserve hard links when committing a container, so a file with multiple names is stored once in the resulting image layer instead of once per name. moby/moby#53624
Packaging updates
- Update containerd (static binaries) to v2.3.5. moby/moby#53589
Networking
- Fix
GET /networksreturning a 500 status if an invalid 'type' filter was provided. moby/moby#53678
v29.8.0
29.8.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
- Add
HostConfig.Umaskoption and a corresponding--umask <octal>flag todocker create/docker runto set the umask for a container's main process, execs, and healthchecks. moby/moby#53463, docker/cli#7108 - Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the
awslogslogging driver. moby/moby#52632
Security
- Add daemon support for configuring the default container AppArmor profile template. moby/moby#52771
- Prevent containers from using the 32-bit
socketcall(2)path to createAF_VSOCKsockets and communicate with host virtual machines by adding AppArmor and SELinux policy rules. moby/moby#53551
Networking
- Fix
docker network inspectfailing to find a healthy Swarm network when another Swarm network could not be allocated. moby/moby#53325 - Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key. moby/moby#53479
- Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement. moby/moby#53437
- Fix Swarm service names failing to resolve on healthy nodes after a transient node failure. moby/moby#53142
- Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe. moby/moby#53517
- Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster. moby/moby#53479
- Remote network-driver plugins can now set the container-side interface name via the
DstNamefield in theirJoinresponse. moby/moby#52866 - Reserve network names "container" and "container:" to prevent creation of unusable networks. moby/moby#51973
- Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage. moby/moby#53475
- Swarm service-mesh published ports now use the same infrastructure as published ports for local containers. moby/moby#53118
Rootless
- Fix
--disable-host-loopbacknot being enforced for thepastanetwork driver in rootless mode. moby/moby#53358 - Update RootlessKit to v3.1.0, adding support for the
pestoport driver in rootless mode. SetDOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pestoto use it; it requires thepastanetwork driver and supports IPv4 only. moby/moby#53358
Go SDK
- Update minimum supported Go version to 1.26. docker/cli#7258
Bug fixes and enhancements
- Add
annotationfilter to container listings (docker ps,GET /containers/json) allowing to filter containers by their annotations. moby/moby#53538 - containerd image store: Fix
docker image inspectreporting a smaller image size thandocker image ls. moby/moby#53426 - containerd image store: Fix slower image pulls caused by repeated registry authentication within a single pull. moby/moby#53497
- Do not log expected image signature identity misses as errors for containerd image store images. moby/moby#53495
- dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed. moby/moby#53388
- Fix
GET /images/{name}/jsonnot including unpacked snapshot usage inSizewhen using the containerd image store. moby/moby#53426 - Fix classic-builder cache for Dockerfile stages that select a non-host platform with
FROM --platform. moby/moby#53503 - Fix CLI panic when
DOCKER_HOSTor-Hspecifies an invalid host. docker/cli#7280 - Fix health checks being delayed for too long when the start interval is longer than the start period. moby/moby#52317
- Fix inconsistent mount ordering in
docker inspectoutput (GET /containers/{id}/json) and container listings (docker ps,GET /containers/json). moby/moby#53534 - Fix NRI container metadata so
Container.Argsincludes the resolved executable asargv[0], matching the process launched in the container instead of only the DockerCmd. moby/moby#53423 - Fix Swarm service creation failing when an automatically generated name is already in use. moby/moby#53468
- Fix the container root directory
/being world-writable when using thebtrfsstorage driver. moby/moby#53500 - Fixed
docker pssorting published ports lexicographically instead of numerically. docker/cli#7144 - Preserve service mount order during forced updates to avoid an unnecessary rollout on the next stack deploy. docker/cli#7227
- Prevent containerd's v2 CRI plugins from loading when CRI is disabled. moby/moby#53564
- Print plugin hook output (e.g. the "What's next:" hint) after the command's error message instead of before it. docker/cli#6976
- Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory. moby/moby#53377
Packaging updates
- Update BuildKit to v0.33.0. moby/moby#53554
- Update containerd (static binaries) to v2.3.4. moby/moby#53409
- Update Go runtime to 1.26.8. moby/moby#53550, docker/cli#7274
- Update runc (in static binaries) to v1.5.1. moby/moby#52306