Executive brief
Kaniko, a tool used to build container images within Kubernetes and other container environments, contains a security flaw in how it handles file extraction. An attacker can provide a specially crafted build file that writes data to unauthorized locations on the host system. In certain configurations, this can be used to take control of the image building process and execute malicious code, potentially compromising the security of the build pipeline.
Technical details
A path traversal vulnerability (CWE-22) exists in kaniko's archive extraction logic. The tool uses `filepath.Join(dest, cleanedName)` to unpack build context archives without verifying that the resulting path remains within the target destination directory. By including tar entries with parent directory references (e.g., `../outside.txt`), an attacker can write files to arbitrary locations. In environments utilizing registry authentication, this primitive can be leveraged to overwrite docker credential helpers, leading to remote code execution (RCE) within the kaniko executor process. The issue is resolved in version 1.25.10 by implementing `securejoin` for path resolution.
Affected products
- Google / Chainguard-forks kaniko >= 1.25.4, < 1.25.10
- Red Hat OpenShift Serverless 1
Timeline
- 2026-02-26: other: Fix developed and pull request opened
- 2026-02-27: patched: Fix merged and version 1.25.10 released
- 2026-02-27: advisory: Initial advisory published by GitHub/Chainguard-forks
- 2026-02-27: disclosed: CVE-2026-28406 published
References
- https://github.com/chainguard-forks/kaniko/commit/a370e4b1f66e6e842b685c8f70ed507964c4b221
- https://github.com/chainguard-forks/kaniko/pull/326
- https://github.com/chainguard-forks/kaniko/security/advisories/GHSA-6rxq-q92g-4rmf
- https://access.redhat.com/security/cve/CVE-2026-28406
- https://bugzilla.redhat.com/show_bug.cgi?id=2443462
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28406.json