Skip to content
DockerCVE-2026-17106

Docker CLI: link following

High7.1CVE-2026-17106 · Published Aug 18, 2026 · updated Aug 28, 2026

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

Docker advisory

Affected versions

PackageAffectedFixed in
Docker CLI
Product
< 29.7.029.7.0
Docker Compose
Product
< 5.4.05.4.0
Docker Desktop
Product
< 4.86.04.86.0
Docker Engine
Product
< 29.7.029.7.0
Docker Sandboxes
Product
< 0.38.00.38.0
go-archive
Product
< 0.3.00.3.0
Details and references

More Docker advisories

All Docker
Advisory
Docker Sandboxes: code execution
Critical9.4Sep 15
Docker Sandboxes: improper authorization
Medium5.7Aug 12
Docker BuildKit: improper input validation
Medium6.0Jul 21
Docker BuildKit: argument injection
High7.3Jul 21
Docker BuildKit: authentication bypass
Medium6.9Jul 21
Docker BuildKit: path traversal
Low1.8Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.