CVE-2026-28406
kaniko has tar archive path traversal in its build context extraction, allowing file writes outside destination directories in github.com/chainguard-dev/kaniko
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/chainguard-forks/kaniko/security/advisories/GHSA-6rxq-q92g-4rmf, https://nvd.nist.gov/vuln/detail/CVE-2026-28406, https://github.com/chainguard-forks/kaniko/commit/a370e4b1f66e6e842b685c8f70ed507964c4b221, https://github.com/chainguard-forks/kaniko/pull/326, https://github.com/chainguard-forks/kaniko/releases/tag/v1.25.10
