Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-17106

PUBLISHED 19.08.2026

CNA: Docker

Tar extraction in moby/go-archive can write outside the destination directory via link following

Обновлено: 18.08.2026
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

CWE

Идентификатор Описание
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

CVSS

Оценка Severity Версия Базовый вектор
7.1 HIGH 4.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.33% LOW 24.97 30.08.2026

Доп. Информация

Product Status

go-archive
Product: go-archive
Vendor: moby
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 0.3.0 affected
Docker Sandboxes
Product: Docker Sandboxes
Vendor: Docker
Default status: unaffected
Platforms:
  • MacOS
  • Linux
  • Windows
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 0.38.0 affected
СPE:
  • cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*
Docker Desktop
Product: Docker Desktop
Vendor: Docker
Default status: unaffected
Platforms:
  • MacOS
  • Linux
  • Windows
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 4.86.0 affected
СPE:
  • cpe:2.3:a:docker:desktop:*:*:*:*:*:*:*:*
Docker Engine
Product: Docker Engine
Vendor: Docker
Default status: unaffected
Platforms:
  • MacOS
  • Linux
  • Windows
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 29.7.0 affected
Docker CLI
Product: Docker CLI
Vendor: Docker
Default status: unaffected
Platforms:
  • MacOS
  • Linux
  • Windows
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 29.7.0 affected
Docker Compose
Product: Docker Compose
Vendor: Docker
Default status: unaffected
Platforms:
  • MacOS
  • Linux
  • Windows
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 5.4.0 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 19.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
poc no total 2.0.3 18.08.2026

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.