VDB
Sign up
—

GO-2025-4077

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations in github.com/docker/compose

Quick fix

GO-2025-4077 — github.com/docker/compose/v2: upgrade to the fixed version with the command below.

go get github.com/docker/compose/v2@v2.40.2

Details

Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations in github.com/docker/compose

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/docker/compose
Introduced in: 0

No fixed version published yet for github.com/docker/compose (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/docker/compose/v2
Introduced in: 0Fixed in: 2.40.2
Fixgo get github.com/docker/compose/v2@v2.40.2

References