PT-2026-108050 · Github · Moby/Sys/User

CVE-2026-61801

·

Published

2026-09-14

·

Updated

2026-10-08

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions github.com/moby/sys/user versions prior to 0.4.1
Description The github.com/moby/sys/user package, which provides Go utilities for parsing and looking up entries in Unix-style user and group database files, does not sufficiently limit entries when parsing /etc/passwd or /etc/group style files. An attacker who can supply a specially crafted file can cause excessive memory consumption, potentially leading to process termination due to an out-of-memory (OOM) condition, which is a state where the system cannot allocate more memory to a process.
Recommendations Update to version 0.4.1 or later. Avoid parsing attacker-controlled user or group database files. Validate and limit untrusted input before parsing it.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61801
GHSA-MJCV-P78Q-W5FW

Affected Products

Moby/Sys/User