Path Traversal Vulnerability in Kaniko Container Image Builder
CVE-2026-28406

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
27 February 2026

What is CVE-2026-28406?

The vulnerability in Kaniko, a container image builder, arises from improper handling of build context archives during the extraction process. Versions ranging from 1.25.4 to 1.25.9 fail to validate the final path of extracted files, potentially allowing malicious tar entries to escape the designated extraction root. This flaw can lead to unauthorized file access or manipulation, particularly in environments utilizing docker credential helpers, thus enabling a chain of code execution within the executor process. Users are strongly advised to upgrade to version 1.25.10 or later, which incorporates secure joining practices for improved path resolution.

Affected Version(s)

kaniko >= 1.25.4, < 1.25.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.