Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction
Summary
| CVE | CVE-2026-107174 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-07 15:17:19 UTC |
| Updated | 2026-10-07 17:16:53 UTC |
| Description | A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system. |
Risk And Classification
Primary CVSS: v3.1 6.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Problem Types: CWE-61 | CWE-61 UNIX Symbolic Link (Symlink) Following
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 6.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | OpenShift Serverless | Not specified | Not specified |
| CNA | Red Hat | OpenShift Serverless | Not specified | Not specified |
| CNA | Red Hat | OpenShift Serverless | Not specified | Not specified |
| CNA | Red Hat | OpenShift Source-to-Image S2I | Not specified | Not specified |
| CNA | Red Hat | OpenShift Source-to-Image S2I | Not specified | Not specified |
| CNA | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| CNA | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Web Terminal | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-107174 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Yashashree Gund for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-10-07T12:27:13.541Z | Reported to Red Hat. |
| CNA | 2026-10-07T12:58:45.168Z | Made public. |
Workarounds
CNA: Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified. Where possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images. There is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream.