What is CVE-2026-17106?
CVE-2026-17106 is a vulnerability in moby/go-archive's tar extraction routines (like Unpack, Untar) where filesystem operations are not properly confined to the destination directory. This allows an attacker to write files to arbitrary locations through a crafted archive. Affected users should immediately update to a patched version.
Azərbaycanca: CVE-2026-17106, moby/go-archive kitabxanasındakı tar arxiv çıxarma prosedurlarında (Unpack, Untar kimi) aşkar edilmiş bir boşluqdur. Bu zəiflik, fayl sistemi əməliyyatlarının təyinat qovluğu ilə məhdudlaşmamasına səbəb olur və təcavüzkara arxiv daxilindəki faylları istənilən yerə yazmağa imkan verə bilər. Təsirə məruz qalan istifadəçilər dərhal patç edilmiş versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ1
Which functions in the moby/go-archive library are affected by CVE-2026-17106?
CVE-2026-17106 affects tar extraction routines in the moby/go-archive library, specifically functions like Unpack and Untar.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.