VDB
CVE-2026-17106
CVE-2026-17106
PUBLISHED
CVSS 7.099999904632568 HIGH
Tar extraction in moby/go-archive can write outside the destination directory via link following
EPSS 0.33% · 25.8th percentile
Risk Scores
CVSS 4.0
7.099999904632568
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
0.33%
25.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| moby | go-archive | |
| Bitnami | docker-cli | 0 |
Timeline
- Jul 30, 2026 CVE Published
- Aug 21, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
- Sep 1, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 15, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- https://docs.docker.com/desktop/release-notes/#4860 url
- https://docs.docker.com/engine/release-notes/29/#2970 url
- https://github.com/masasron/CopyEscape-CVE-2026-17106 url
- https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h url
- https://nvd.nist.gov/vuln/detail/CVE-2026-17106 url
- https://github.com/docker/cli/releases/tag/v29.7.0 fix
- https://github.com/docker/compose/releases/tag/v5.4.0 fix
- https://github.com/docker/sbx-releases/releases/tag/v0.38.0 fix
- https://github.com/moby/go-archive/releases/tag/v0.3.0 fix