CVE-2026-17106: Docker CLI

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.

Affected products

  • Docker Docker CLI: before 29.7.0 (fixed in 29.7.0)
  • Docker Docker Compose: before 5.4.0 (fixed in 5.4.0)
  • Docker Docker Desktop: before 4.86.0 (fixed in 4.86.0)
  • Docker Docker Engine: before 29.7.0 (fixed in 29.7.0)
  • Docker Docker Sandboxes: before 0.38.0 (fixed in 0.38.0)
  • Moby Go-Archive: before 0.3.0 (fixed in 0.3.0)

Published 2026-08-18. Last modified 2026-08-28.