A vulnerability exists in Docker where a malicious container image can execute arbitrary code with host root privileges by exploiting the decompression of compressed archives uploaded via the `PUT /containers/{id}/archive` endpoint, tracked as CVE-2026-41567.
PoC
Docker +2
container
rce
privilege-escalation
CVE-2026-41567
2r
1t
1c
updated