{"api_version":"1","generated_at":"2026-10-08T06:11:03+00:00","cve":"CVE-2026-107174","urls":{"html":"https://cve.report/CVE-2026-107174","api":"https://cve.report/api/cve/CVE-2026-107174.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107174","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107174"},"summary":{"title":"Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction","description":"A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-10-07 15:17:19","updated_at":"2026-10-07 17:16:53"},"problem_types":["CWE-61","CWE-61 UNIX Symbolic Link (Symlink) Following"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547419","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2547419","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-107174","name":"https://access.redhat.com/security/cve/CVE-2026-107174","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107174","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107174","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"OpenShift Serverless","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"OpenShift Serverless","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"OpenShift Serverless","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"OpenShift Source-to-Image (S2I)","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"OpenShift Source-to-Image (S2I)","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Web Terminal","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-10-07T12:27:13.541Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-10-07T12:58:45.168Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified.\n\nWhere possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images.\n\nThere is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Red Hat would like to thank Yashashree Gund for reporting this issue.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-107174","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-07T16:17:10.638072Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-07T16:17:28.174Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:serverless:1"],"defaultStatus":"affected","packageName":"openshift-serverless-1/kn-client-kn-rhel9","product":"OpenShift Serverless","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:serverless:1"],"defaultStatus":"affected","packageName":"openshift-serverless-1/kn-plugin-func-func-util-rhel9","product":"OpenShift Serverless","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:serverless:1"],"defaultStatus":"affected","packageName":"openshift-serverless-clients","product":"OpenShift Serverless","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:source_to_image:1"],"defaultStatus":"affected","packageName":"source-to-image/source-to-image-rhel8","product":"OpenShift Source-to-Image (S2I)","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:source_to_image:1"],"defaultStatus":"affected","packageName":"source-to-image/source-to-image-rhel9","product":"OpenShift Source-to-Image (S2I)","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift4/ose-docker-builder","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift4/ose-docker-builder-rhel9","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:webterminal:1"],"defaultStatus":"affected","packageName":"web-terminal/web-terminal-tooling-rhel9","product":"Red Hat Web Terminal","vendor":"Red Hat"}],"credits":[{"lang":"en","value":"Red Hat would like to thank Yashashree Gund for reporting this issue."}],"datePublic":"2026-10-07T12:58:45.168Z","descriptions":[{"lang":"en","value":"A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-61","description":"UNIX Symbolic Link (Symlink) Following","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-07T14:34:51.439Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-107174"},{"name":"RHBZ#2547419","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547419"}],"timeline":[{"lang":"en","time":"2026-10-07T12:27:13.541Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-07T12:58:45.168Z","value":"Made public."}],"title":"Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction","workarounds":[{"lang":"en","value":"Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified.\n\nWhere possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images.\n\nThere is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-61: UNIX Symbolic Link (Symlink) Following"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-107174","datePublished":"2026-10-07T14:34:51.439Z","dateReserved":"2026-10-07T12:26:30.460Z","dateUpdated":"2026-10-07T16:17:28.174Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-07 15:17:19","lastModifiedDate":"2026-10-07 17:16:53","problem_types":["CWE-61","CWE-61 UNIX Symbolic Link (Symlink) Following"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","baseScore":6.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.1,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-07T16:17:10.638072Z","id":"CVE-2026-107174","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107174","Ordinal":"1","Title":"Source-to-image: source-to-image: security boundary bypass via a","CVE":"CVE-2026-107174","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107174","Ordinal":"1","NoteData":"A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.","Type":"Description","Title":"Source-to-image: source-to-image: security boundary bypass via a"}]}}}