PT-2026-107537 · Red Hat · Openshift Serverless+3

CVE-2026-107174

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107174

Affected Products

Openshift Serverless
Openshift Source-To-Image
Red Hat Openshift Container Platform 4
Red Hat Web Terminal