Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified. Where possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images. There is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system. | |
| Title | Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction | |
| First Time appeared |
Redhat
Redhat openshift Redhat serverless Redhat source To Image Redhat webterminal |
|
| Weaknesses | CWE-61 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/a:redhat:serverless:1 cpe:/a:redhat:source_to_image:1 cpe:/a:redhat:webterminal:1 |
|
| Vendors & Products |
Redhat
Redhat openshift Redhat serverless Redhat source To Image Redhat webterminal |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T16:17:28.174Z
Reserved: 2026-10-07T12:26:30.460Z
Link: CVE-2026-107174
No data.
Status : Awaiting Analysis
Published: 2026-10-07T15:17:19.190
Modified: 2026-10-07T17:16:53.380
Link: CVE-2026-107174
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:30:17Z