{"id":"CVE-2026-17106","aliases":["BIT-docker-cli-2026-17106","GHSA-hfg8-hc9c-6c3h","GO-2026-6253"],"url":"https://o3.security/vulnerability/CVE-2026-17106","summary":"Tar extraction in moby/go-archive can write outside the destination directory via link following","details":"### Summary\nThe tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination. \n\n### Details\nThe extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so a links introduced by the archive can be followed out of the destination directory.\n\n### Impact\nAn attacker who controls the contents of archive can create or overwrite files at arbitrary paths writable by the extracting process.\n\n### Workarounds\nOnly extract trusted archives.","published":"2026-08-18T18:35:13.465Z","modified":"2026-09-29T18:26:41.481905420Z","cvss":null,"epss":{"score":0.00325,"percentile":0.25631,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"github.com/moby/go-archive","fixedVersion":"0.3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://docs.docker.com/desktop/release-notes/#4860"},{"type":"ADVISORY","url":"https://docs.docker.com/engine/release-notes/29/#2970"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17106.json"},{"type":"ADVISORY","url":"https://github.com/docker/cli/releases/tag/v29.7.0"},{"type":"ADVISORY","url":"https://github.com/docker/compose/releases/tag/v5.4.0"},{"type":"ADVISORY","url":"https://github.com/docker/sbx-releases/releases/tag/v0.38.0"},{"type":"ADVISORY","url":"https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17106"},{"type":"FIX","url":"https://github.com/moby/go-archive/releases/tag/v0.3.0"},{"type":"EVIDENCE","url":"https://github.com/masasron/CopyEscape-CVE-2026-17106"},{"type":"WEB","url":"https://github.com/moby/moby/issues/52948"},{"type":"WEB","url":"https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape"},{"type":"PACKAGE","url":"https://github.com/moby/go-archive"},{"type":"WEB","url":"https://github.com/moby/moby/releases/tag/docker-v29.7.0"},{"type":"WEB","url":"https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-29T18:26:41.481905420Z"}}