THREAT OPS › Threat News › [GHSA] GHSA-hfg8-hc9c-6c3h (high) — moby/go-archive: Crafted tar archive can write outside the extraction directory
[GHSA] GHSA-hfg8-hc9c-6c3h (high) — moby/go-archive: Crafted tar archive can write outside the extraction directory
GHSA-hfg8-hc9c-6c3h Severity: high CVE: CVE-2026-17106
moby/go-archive: Crafted tar archive can write outside the extraction directory
### Summary The tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **
Indicators of compromise
- CVE-2026-17106cve
Original source: https://github.com/advisories/GHSA-hfg8-hc9c-6c3h