Symlink Attack Affecting github.com/moby/go-archive package, versions <0.3.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.33% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMOBYGOARCHIVE-18958666
  • published19 Aug 2026
  • disclosed18 Aug 2026
  • creditUnknown

Introduced: 18 Aug 2026

NewCVE-2026-17106  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade github.com/moby/go-archive to version 0.3.0 or higher.

Overview

Affected versions of this package are vulnerable to Symlink Attack through the Unpack and UnpackLayer routines in archive.go and diff.go. An attacker can create or overwrite files outside the intended extraction directory by supplying a crafted archive with traversal entries or symlink chains during extraction. The vulnerable code relies on lexical path checks while resolving archive entries on filesystem paths the OS can follow, so extracted content can escape the destination root and affect arbitrary writable files on the host.

CVSS Base Scores

version 4.0
version 3.1