THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hfg8-hc9c-6c3h (high) — moby/go-archive: Crafted tar archive can write outside the extraction directory

[GHSA] GHSA-hfg8-hc9c-6c3h (high) — moby/go-archive: Crafted tar archive can write outside the extraction directory

medgithub_advisoriesPublished 2026-08-18

GHSA-hfg8-hc9c-6c3h Severity: high CVE: CVE-2026-17106

moby/go-archive: Crafted tar archive can write outside the extraction directory

### Summary The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hfg8-hc9c-6c3h