{"id":"CVE-2026-17106","summary":"Tar extraction in moby/go-archive can write outside the destination directory via link following","details":"The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.","aliases":["GHSA-hfg8-hc9c-6c3h"],"modified":"2026-08-23T18:50:34.828156904Z","published":"2026-08-18T18:35:13.465Z","related":["CGA-hj86-cwfh-8vvv","openSUSE-SU-2026:11544-1","openSUSE-SU-2026:21611-1"],"database_specific":{"cwe_ids":["CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17106.json","unresolved_ranges":[{"extracted_events":[{"fixed":"4.86.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"Docker"},"references":[{"type":"ADVISORY","url":"https://docs.docker.com/desktop/release-notes/#4860"},{"type":"ADVISORY","url":"https://docs.docker.com/engine/release-notes/29/#2970"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17106.json"},{"type":"ADVISORY","url":"https://github.com/docker/cli/releases/tag/v29.7.0"},{"type":"ADVISORY","url":"https://github.com/docker/compose/releases/tag/v5.4.0"},{"type":"ADVISORY","url":"https://github.com/docker/sbx-releases/releases/tag/v0.38.0"},{"type":"ADVISORY","url":"https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17106"},{"type":"FIX","url":"https://github.com/moby/go-archive/releases/tag/v0.3.0"},{"type":"EVIDENCE","url":"https://github.com/masasron/CopyEscape-CVE-2026-17106"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/docker/cli","events":[{"introduced":"0"},{"fixed":"c1eba931e3d15d204bedeadeb55ad8880be14ad3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"29.7.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/docker/compose","events":[{"introduced":"0"},{"fixed":"8c16961afd869172e02db2797f7787e8367c7b83"},{"fixed":"ef61d7410a0c816a71705026e638ec256a591d69"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.3.0"},{"fixed":"5.4.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}},{"type":"GIT","repo":"https://github.com/docker/sbx-releases","events":[{"introduced":"0"},{"fixed":"e4809b108ff941fbd3dc8ab1edd8755af78ddc07"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"0.38.0"}]}},{"type":"GIT","repo":"https://github.com/moby/go-archive","events":[{"introduced":"0"},{"fixed":"1c23372e409716c3691a540871806083644f348a"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v29.7.0-rc.1","v29.6.1","v29.6.0","v29.5.3","v29.5.2","v29.5.1","v29.5.0","v29.4.3","v29.4.2","v29.4.1","v29.4.0-rc.1","v29.4.0","v29.6.0-rc.1","v29.5.0-rc.1","v29.3.0","v29.3.0-rc.1","v29.2.1","v29.2.0","v29.2.0-rc.2","v29.2.0-rc.1","v29.1.5","v29.1.4","v29.1.3","v29.1.2","v29.1.1","v29.1.0","v29.0.4","v29.0.3","v29.1.0-rc.1","v29.0.2","v29.0.1","v29.0.0","v29.0.0-rc.3","v29.0.0-rc.2","v29.0.0-rc.1","v28.3.3","v28.3.2","v28.3.1","v28.3.0","v28.3.0-rc.2","v28.3.0-rc.1","v28.2.2","v28.2.1","v28.2.0","v28.2.0-rc.2","v28.2.0-rc.1","v28.1.1","v28.1.0","v28.1.0-rc.2","v28.1.0-rc.1","v28.0.4","v28.0.3","v28.0.2","v28.0.1","v28.0.0","v28.0.0-rc.3","v28.0.0-rc.2","v28.0.0-rc.1","v27.0.1","v27.0.1-rc.1","v27.0.0-rc.2","v27.0.0-rc.1","v26.1.0","v26.0.0","v26.0.0-rc3","v26.0.0-rc2","v26.0.0-rc1","v25.0.0","v25.0.0-rc.3","v25.0.0-rc.2","v25.0.0-rc.1","v25.0.0-beta.3","v25.0.0-beta.2","v25.0.0-beta.1","v24.0.0-rc.2","v24.0.0-rc.1","v24.0.0-beta.2","v24.0.0-beta.1","v23.0.0-rc.4","v23.0.0","v23.0.0-rc.3","v23.0.0-rc.2","v23.0.0-rc.1","v23.0.0-beta.1","v22.06.0-beta.0","v20.10.2","v20.10.1","v20.10.0","v20.10.0-rc2","v20.10.0-rc1","v20.10.0-beta1","v19.03.0-beta3","v19.03.0-beta2","v19.03.0-beta1","v18.09.0-ce-tp4","v18.09.0-ce-tp3","v18.09.0-ce-tp0","v18.06.0-ce-rc1","v5.3.1","v5.3.0","v5.2.0","v5.1.4","v5.1.3","v5.1.2","v5.1.1","v5.1.0","v5.0.2","v5.0.1","v5.0.0","v5.0.0-rc.2","v5.0.0-rc.1","v2.40.2","v2.40.1","v2.40.0","v2.39.4","v2.39.3","v2.39.2","v2.39.1","v2.39.0","v2.38.2","v2.38.1","v2.38.0","v2.37.3","v2.37.2","v2.37.1","v2.37.0","v2.36.2","v2.36.1","v2.36.0","v2.35.1","v2.35.0","v2.34.0","v2.33.1","v2.33.0","v2.32.4","v2.32.3","v2.32.2","v2.32.1","v2.32.0","v2.31.0","v2.30.3","v2.30.2","v2.30.1","v2.30.0","v2.29.7","v2.29.6","v2.29.5","v2.29.4","v2.29.3","v2.29.2","v2.29.1","v2.29.0","v2.28.1","v2.28.0","v2.27.3","v2.27.2","v2.27.1","v2.27.0","v2.26.1","v2.26.0","v2.25.0","v2.24.7","v2.24.6","v2.24.5","v2.24.4","v2.24.3","v2.24.2","v2.24.1","v2.24.0","v2.24.0-birthday.10","v2.23.3","v2.23.2","v2.23.1","v2.23.0","v2.22.0","v2.21.0","v2.20.3","v2.20.2","v2.20.1","v2.20.0","v2.19.1","v2.19.0","v2.18.1","v2.18.0","v2.17.3","v2.17.2","v2.17.1","v2.17.0","v2.17.0-rc.1","v2.16.0","v2.15.1","v2.15.0","v2.14.2","v2.14.1","v2.14.0","v2.13.0","v2.12.2","v2.12.1","v2.12.0","v2.11.2","v2.11.1","v2.11.0","v2.10.2","v2.10.1","v2.10.0","v2.9.0","v2.8.0","v2.7.0","v2.6.1","v2.6.0","v2.5.1","v2.5.0","v2.4.1","v2.4.0","v2.3.4","v2.3.3","v2.3.2","v2.3.1","v2.3.0","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.1","v2.1.0","v2.0.1","v2.0.0","v2.0.0-rc.4","v2.0.0-rc.3","0.2.2","0.2.1","0.2.0","0.1.4","0.1.3","0.1.2","0.1.1","0.1.0","0.0.2","0.0.1","v0.31.0-rc1","v0.30.0-rc2","v0.30.0-rc1","v0.30.0","v0.29.0-rc1","v0.29.0","v0.28.3","v0.28.2","v0.28.1-rc2","v0.28.1","v0.28.0","v0.27.0","v0.26.1","v0.25.0","dev-ebc3fbe","dev-e54ee33","dev-dc73246","dev-c7702ef","dev-c13a59d","dev-bad9503","dev-ad0ca5e","dev-a5207e0","dev-921c1c7","dev-8fc2763","dev-793e764","dev-78ed158","dev-438ebd7","dev-2631810","dev-1f51dc0","dev-02f174c","v0.24.2","v0.24.1","v0.23.0","v0.21.0","v0.20.0","v0.19.0","v0.18.7","v0.18.6","v0.18.5","v0.18.4","v0.18.3","v0.18.2","v0.17.0","v0.16.0","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17106.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}