—
GO-2026-4580
kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directories in github.com/chainguard-dev/kaniko
Quick fix
GO-2026-4580 — github.com/chainguard-dev/kaniko: upgrade to the fixed version with the command below.
go get github.com/chainguard-dev/kaniko@v1.25.10Details
kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directories in github.com/chainguard-dev/kaniko
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/chainguard-dev/kaniko
Introduced in:
1.25.4Fixed in: 1.25.10Fix
go get github.com/chainguard-dev/kaniko@v1.25.10References
- https://github.com/chainguard-forks/kaniko/security/advisories/GHSA-6rxq-q92g-4rmf[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-28406[ADVISORY]
- https://github.com/chainguard-forks/kaniko/commit/a370e4b1f66e6e842b685c8f70ed507964c4b221[WEB]
- https://github.com/chainguard-forks/kaniko/pull/326[WEB]
- https://github.com/chainguard-forks/kaniko/releases/tag/v1.25.10[WEB]