KO: 这是通过超过 1MB 的请求体绕过 Docker(Moby) 授权(AuthZ) 插件的漏洞的实操复现项目。 EN: A lab reproduction of a vulnerability that bypasses Docker (Moby) authorization (AuthZ) plugins using an oversized (>1MB) request body.
| Item | Value |
|---|---|
| CVE | CVE-2026-34040 |
| CVSS 3.1 | 8.8 (High) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CWE | CWE-288 (Authentication Bypass Using an Alternate Path or Channel), CWE-863 (Incorrect Authorization) |
| Affected | moby/moby < 29.3.1, docker/docker < 29.3.1, moby/moby/v2 < 2.0.0-beta.8 |
| Fixed in | 29.3.1, 2.0.0-beta.8 |
| Root cause | Incomplete fix for CVE-2024-41110 |
| Patch commit | moby/moby@e89edb1 |
KO: 官方 CVSS 向量是
AV:L(本地)。即评估标准是具有本地 Docker API 访问权限(通常是/var/run/docker.sock)的低权限用户。这个 PoC 也只使用本地 UNIX socket。 EN: The official CVSS vector isAV:L(Local). The rated scenario is a low-privileged user with local Docker API access (typically/var/run/docker.sock). This PoC uses the local UNIX socket only.
KO:
- 正常大小的特权容器创建请求会被 AuthZ 插件阻止 (HTTP 403)。
- 包含超过 1MB padding 的相同请求会绕过 AuthZ 检查。
- 被绕过的请求到达 Docker Daemon 处理阶段,创建特权容器。
- 通过 privileged + 主机 bind mount 组合,可以演示主机文件读取和主机命令执行。
EN:
- A normal-sized privileged container-create request is blocked by the AuthZ plugin (HTTP 403).
- The same request padded beyond 1MB bypasses the AuthZ check.
- The bypassed request reaches the Docker daemon and creates a privileged container.
- With privileged + host bind mount, host file read and host command execution can be demonstrated.
KO: 这个 CVE 本身不会直接读取
/etc/shadow或执行 RCE。漏洞的本质是绕过 AuthZ 应阻止的 Docker API 请求;后续步骤(文件读取、chroot、命令执行)是利用 Docker/Linux 正常功能的影响演示。 EN: The CVE itself does not read/etc/shadowor perform RCE directly. The vulnerability is the bypass of a Docker API request that AuthZ should block; the later steps (file read, chroot, command execution) are impact demos that abuse normal Docker/Linux features.
.
├── README.md
├── poc.py # Working PoC (local UNIX socket only)
├── requirements.txt # Python standard library only
├── LICENSE
├── lab/
│ ├── authz.rego # OPA policy: blocks privileged + host-root bind
│ └── daemon.json # Registers the AuthZ plugin
└── docs/
├── concepts.md # 개념 / Concepts
├── lab-setup.md # 환경 구성 / Lab setup
├── how-it-works.md # 동작 원리 / How it works (source-level)
├── usage.md # 사용법 / Usage
├── troubleshooting.md # 문제 해결 / Troubleshooting
└── references.md # 참고 / References
KO: 要让这个 PoC 有意义地运行,需要满足以下所有条件。 EN: All of the following are required for this PoC to be meaningful.
# 1) Pull the image used by the PoC
sudo docker pull alpine
# 2) Run the non-destructive bypass check
sudo python3 poc.py --mode check
Expected on a vulnerable target / 易受攻击目标上的预期结果:
small request -> HTTP 403 (AuthZ blocks)
oversized request -> HTTP 201 or HTTP 404 (AuthZ bypassed; daemon processed it)
KO:
404 No such image也是绕过的证据。这意味着请求没有被 AuthZ 阻止(403),而是到达了 Docker Daemon 的镜像检查阶段。在演示/展示时,请提前 pullalpine以避免混淆。 EN: A404 No such imageis still evidence of bypass — the request passed AuthZ (not 403) and reached the daemon's image lookup. Pullalpinebeforehand to avoid confusion in a demo.
完整用法参见 docs/usage.md。 / See docs/usage.md for full usage.
KO: 请仅在自己拥有或明确获准测试的隔离实验环境中使用。不要针对远程 Docker API、第三方服务器、生产环境或暴露在互联网上的 Docker endpoint 运行。影响演示模式(
rce-proof、host-command、reverse-shell-local)需要显式确认标志才能运行。 EN: Use only in an isolated lab you own or are explicitly authorized to test. Do not run against remote Docker APIs, third-party servers, production, or internet-exposed Docker endpoints. The impact-demo modes (rce-proof,host-command,reverse-shell-local) require an explicit confirmation flag.
See docs/references.md. / docs/references.md 参见。
| Condition | Required | Reason |
|---|
Local Docker API access (/var/run/docker.sock) | Yes | The PoC sends requests to the socket |
| AuthZ plugin enabled with a body-inspecting policy | Yes | The bypass target is the AuthZ check |
| Docker/Moby < 29.3.1 | Yes | Patched versions reject oversized bodies |
alpine image present locally | Recommended | Otherwise create returns 404 No such image |