Tar extraction in moby/go-archive can write outside the destination directory via link following
41Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 7.1epss 0.2%
da publicação à arma0 dias
Publicada no NVD18 de ago.
1ª PoC11 de ago.
probabilidade de exploração
0.2%top 91% das CVEs
exploração observada
nãonenhuma fonte reporta
3 exploit(s) público(s)
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Docker · Docker CLIDocker · Docker ComposeDocker · Docker DesktopDocker · Docker EngineDocker · Docker Sandboxesmoby · go-archivePoCs públicas encontradas — 3
cve_referencegithub.com/masasron/CopyEscape-CVE-2026-17106★ 17githubgithub.com/HackSpeak/CVE-2026-17106★ 1githubgithub.com/686f6c61/POC-CopyEscape-CVE-2026-17106★ 1⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://docs.docker.com/desktop/release-notes/#4860https://docs.docker.com/engine/release-notes/29/#2970https://github.com/docker/cli/releases/tag/v29.7.0https://github.com/docker/compose/releases/tag/v5.4.0https://github.com/docker/sbx-releases/releases/tag/v0.38.0https://github.com/masasron/CopyEscape-CVE-2026-17106https://github.com/moby/go-archive/releases/tag/v0.3.0https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h