CVE-2026-61801: Moby Sys

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.

Affected products

  • Moby Sys: before 0.4.1 (fixed in 0.4.1)

Published 2026-10-08. Last modified 2026-10-08.