« Volver al listado

CVE-2026-17106

Estado: Pendiente de análisisAlta (7.1)—

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L + UI:A indica explotación en cliente (abrir archivo TAR preparado). El atacante sobrescribe archivos arbitrarios via symlinks, logrando manipulación de datos y potencialmente escalada (CWE-59: path traversal).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-17106",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-17106",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-18T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@docker.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "ACTIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@docker.com",
      "affectedData": [
        {
          "vendor": "moby",
          "product": "go-archive",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.3.0",
              "versionType": "semver"
            }
          ],
          "packageName": "github.com/moby/go-archive",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:docker:docker_sandboxes:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Docker",
          "product": "Docker Sandboxes",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "0.38.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MacOS",
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:2.3:a:docker:desktop:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Docker",
          "product": "Docker Desktop",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.86.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MacOS",
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Docker",
          "product": "Docker Engine",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "29.7.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MacOS",
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Docker",
          "product": "Docker CLI",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "29.7.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MacOS",
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Docker",
          "product": "Docker Compose",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "5.4.0",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "MacOS",
            "Linux",
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-18T19:16:45.030",
  "references": [
    {
      "url": "https://docs.docker.com/desktop/release-notes/#4860",
      "source": "security@docker.com"
    },
    {
      "url": "https://docs.docker.com/engine/release-notes/29/#2970",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/docker/cli/releases/tag/v29.7.0",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/docker/compose/releases/tag/v5.4.0",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/docker/sbx-releases/releases/tag/v0.38.0",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/moby/go-archive/releases/tag/v0.3.0",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h",
      "source": "security@docker.com"
    },
    {
      "url": "https://github.com/masasron/CopyEscape-CVE-2026-17106",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@docker.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process."
    }
  ],
  "lastModified": "2026-08-28T15:29:44.967",
  "sourceIdentifier": "security@docker.com"
}