{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-107174","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-10-07T12:26:30.460Z","datePublished":"2026-10-07T14:34:51.439Z","dateUpdated":"2026-10-07T16:17:28.174Z"},"containers":{"cna":{"title":"Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction","metrics":[{"other":{"content":{"value":"Moderate","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system."}],"affected":[{"vendor":"Red Hat","product":"OpenShift Serverless","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-1/kn-client-kn-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-1/kn-plugin-func-func-util-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Serverless","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-serverless-clients","defaultStatus":"affected","cpes":["cpe:/a:redhat:serverless:1"]},{"vendor":"Red Hat","product":"OpenShift Source-to-Image (S2I)","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"source-to-image/source-to-image-rhel8","defaultStatus":"affected","cpes":["cpe:/a:redhat:source_to_image:1"]},{"vendor":"Red Hat","product":"OpenShift Source-to-Image (S2I)","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"source-to-image/source-to-image-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:source_to_image:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-docker-builder","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift4/ose-docker-builder-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift:4"]},{"vendor":"Red Hat","product":"Red Hat Web Terminal","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"web-terminal/web-terminal-tooling-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:webterminal:1"]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107174","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2547419","name":"RHBZ#2547419","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-10-07T12:58:45.168Z","problemTypes":[{"descriptions":[{"cweId":"CWE-61","description":"UNIX Symbolic Link (Symlink) Following","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-61: UNIX Symbolic Link (Symlink) Following","workarounds":[{"lang":"en","value":"Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified.\n\nWhere possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images.\n\nThere is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream."}],"timeline":[{"lang":"en","time":"2026-10-07T12:27:13.541Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-07T12:58:45.168Z","value":"Made public."}],"credits":[{"lang":"en","value":"Red Hat would like to thank Yashashree Gund for reporting this issue."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-10-07T14:34:51.439Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-07T16:17:10.638072Z","id":"CVE-2026-107174","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-07T16:17:28.174Z"}}]}}