CVE-2026-17106

Source
https://cve.org/CVERecord?id=CVE-2026-17106
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17106.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17106
Aliases
Downstream
Related
Published
2026-08-18T18:35:13.465Z
Modified
2026-08-20T03:53:57.659857484Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Tar extraction in moby/go-archive can write outside the destination directory via link following
Details

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "4.86.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "Docker",
    "cwe_ids": [
        "CWE-59"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17106.json"
}
References

Affected packages

Git / github.com/docker/cli

Affected ranges

Type
GIT
Repo
https://github.com/docker/cli
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "29.7.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/docker/compose
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.3.0"
        },
        {
            "fixed": "5.4.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/docker/sbx-releases
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.38.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/moby/go-archive
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.0.1
0.0.2
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.2.0
0.2.1
0.2.2
Other
dev-02f174c
dev-1f51dc0
dev-2631810
dev-438ebd7
dev-78ed158
dev-793e764
dev-8fc2763
dev-921c1c7
dev-a5207e0
dev-ad0ca5e
dev-bad9503
dev-c13a59d
dev-c7702ef
dev-dc73246
dev-e54ee33
dev-ebc3fbe
v0.*
v0.1.0
v0.16.0
v0.17.0
v0.18.2
v0.18.3
v0.18.4
v0.18.5
v0.18.6
v0.18.7
v0.19.0
v0.2.0
v0.2.1
v0.20.0
v0.21.0
v0.23.0
v0.24.1
v0.24.2
v0.25.0
v0.26.1
v0.27.0
v0.28.0
v0.28.1
v0.28.1-rc2
v0.28.2
v0.28.3
v0.29.0
v0.29.0-rc1
v0.30.0
v0.30.0-rc1
v0.30.0-rc2
v0.31.0-rc1
v18.*
v18.06.0-ce-rc1
v18.09.0-ce-tp0
v18.09.0-ce-tp3
v18.09.0-ce-tp4
v19.*
v19.03.0-beta1
v19.03.0-beta2
v19.03.0-beta3
v2.*
v2.0.0
v2.0.0-rc.3
v2.0.0-rc.4
v2.0.1
v2.1.0
v2.1.1
v2.10.0
v2.10.1
v2.10.2
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.12.1
v2.12.2
v2.13.0
v2.14.0
v2.14.1
v2.14.2
v2.15.0
v2.15.1
v2.16.0
v2.17.0
v2.17.0-rc.1
v2.17.1
v2.17.2
v2.17.3
v2.18.0
v2.18.1
v2.19.0
v2.19.1
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.20.0
v2.20.1
v2.20.2
v2.20.3
v2.21.0
v2.22.0
v2.23.0
v2.23.1
v2.23.2
v2.23.3
v2.24.0
v2.24.0-birthday.10
v2.24.1
v2.24.2
v2.24.3
v2.24.4
v2.24.5
v2.24.6
v2.24.7
v2.25.0
v2.26.0
v2.26.1
v2.27.0
v2.27.1
v2.27.2
v2.27.3
v2.28.0
v2.28.1
v2.29.0
v2.29.1
v2.29.2
v2.29.3
v2.29.4
v2.29.5
v2.29.6
v2.29.7
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.30.0
v2.30.1
v2.30.2
v2.30.3
v2.31.0
v2.32.0
v2.32.1
v2.32.2
v2.32.3
v2.32.4
v2.33.0
v2.33.1
v2.34.0
v2.35.0
v2.35.1
v2.36.0
v2.36.1
v2.36.2
v2.37.0
v2.37.1
v2.37.2
v2.37.3
v2.38.0
v2.38.1
v2.38.2
v2.39.0
v2.39.1
v2.39.2
v2.39.3
v2.39.4
v2.4.0
v2.4.1
v2.40.0
v2.40.1
v2.40.2
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.7.0
v2.8.0
v2.9.0
v20.*
v20.10.0
v20.10.0-beta1
v20.10.0-rc1
v20.10.0-rc2
v20.10.1
v20.10.2
v22.*
v22.06.0-beta.0
v23.*
v23.0.0
v23.0.0-beta.1
v23.0.0-rc.1
v23.0.0-rc.2
v23.0.0-rc.3
v23.0.0-rc.4
v24.*
v24.0.0-beta.1
v24.0.0-beta.2
v24.0.0-rc.1
v24.0.0-rc.2
v25.*
v25.0.0
v25.0.0-beta.1
v25.0.0-beta.2
v25.0.0-beta.3
v25.0.0-rc.1
v25.0.0-rc.2
v25.0.0-rc.3
v26.*
v26.0.0
v26.0.0-rc1
v26.0.0-rc2
v26.0.0-rc3
v26.1.0
v27.*
v27.0.0-rc.1
v27.0.0-rc.2
v27.0.1
v27.0.1-rc.1
v28.*
v28.0.0
v28.0.0-rc.1
v28.0.0-rc.2
v28.0.0-rc.3
v28.0.1
v28.0.2
v28.0.3
v28.0.4
v28.1.0
v28.1.0-rc.1
v28.1.0-rc.2
v28.1.1
v28.2.0
v28.2.0-rc.1
v28.2.0-rc.2
v28.2.1
v28.2.2
v28.3.0
v28.3.0-rc.1
v28.3.0-rc.2
v28.3.1
v28.3.2
v28.3.3
v29.*
v29.0.0
v29.0.0-rc.1
v29.0.0-rc.2
v29.0.0-rc.3
v29.0.1
v29.0.2
v29.0.3
v29.0.4
v29.1.0
v29.1.0-rc.1
v29.1.1
v29.1.2
v29.1.3
v29.1.4
v29.1.5
v29.2.0
v29.2.0-rc.1
v29.2.0-rc.2
v29.2.1
v29.3.0
v29.3.0-rc.1
v29.4.0
v29.4.0-rc.1
v29.4.1
v29.4.2
v29.4.3
v29.5.0
v29.5.0-rc.1
v29.5.1
v29.5.2
v29.5.3
v29.6.0
v29.6.0-rc.1
v29.6.1
v29.7.0-rc.1
v5.*
v5.0.0
v5.0.0-rc.1
v5.0.0-rc.2
v5.0.1
v5.0.2
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.1.4
v5.2.0
v5.3.0
v5.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17106.json"