VYPR
High severityNVD Advisory· Published Aug 18, 2026· Updated Aug 28, 2026

CVE-2026-17106

CVE-2026-17106

Description

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/moby/go-archiveGo
< 0.3.00.3.0

Affected products

57

Patches

Vulnerability mechanics

References

12

News mentions

3