CVE-2026-17106High· 7.8▾ MidnightPoC availableA flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.3%
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
7.8 → —
— → 7.8
Last analysed / modified upstream
3 GitHub repos (last check)
A flaw was found in moby/go-archive. The tar extraction routines in the component do not properly restrict filesystem operations to the intended destination directory. An attacker who controls the contents of an archive can exploit this by including symbolic links, allowing them to create or overwrite files at arbitrary locations on the system where the archive is being extracted. This could lead to unauthorized modification of system files or potentially arbitrary code execution.
github.com/moby/go-archive: moby/go-archive: Arbitrary file write via link following in tar extraction — rated Important by Red Hat. Released 2026-08-18, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For OpenShift Container Platform 4.22 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:
For Red Hat OpenShift Logging 6.6, see the following instructions to apply this update:
https://docs.redhat.com/en/documentation/red_hat_openshift_logging/6.6 https://access.redhat.com/errata/RHSA-2026:66521 For more details, see the Red Hat Advanced Cluster Management for Kubernetes documentation:
https://docs.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.17/html/multicluster_global_hub/index https://access.redhat.com/errata/RHSA-2026:68515 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.2 https://access.redhat.com/errata/RHSA-2026:68006
Workarounds / mitigations:
Affected packages:
github.com/moby/go-archive < 0.3.0Patched in:
github.com/moby/go-archive 0.3.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
CVE-2026-79699Medium· 4.4A flaw was found in the containers/storage library
CVE-2026-79705Medium· 4.5A flaw was found in the buildah/copier Go package
CVE-2025-59682High· 8.8django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)