Ron Masas[verified]@RonMasasExploit
CVE-2026-17106, dubbed CopyEscape, allows attackers to use a simple docker cp command to write files to the host and achieve code execution outside the container. The vulnerability is actively exploitable, but no patch or mitigation is mentioned.
ThreatWire[verified]@ThreatWire_Disclosure
The tweet announces CVE-2026-17106, a Docker vulnerability with a CVSS of 7.1 that enables a malicious container to overwrite host files and potentially run code, posing a serious risk for unpatched environments.
Aikido Community Japan[verified]@AikidoCommJPPatch
The post explains the Docker CopyEscape (CVE‑2026‑17106) vulnerability, how docker cp can overwrite host files and lead to takeover, and recommends patching to specified versions along with interim mitigations.
Onur OKTAY[verified]@onuroktayGeneral
A report on CVE-2026-17106 for Docker containers is released, offering high‑level analysis and mitigation suggestions without providing specific exploit code, active exploitation evidence, or patch details.
dbugs[verified]@ptdbugsPoC
A PoC and exploit for CVE-2026-17106 have been released, highlighting a path traversal flaw in Docker's go-archive that permits attackers to write files outside the intended extraction directory.
yousukezan[verified]@yousukezanPoC
Imperva disclosed CVE‑2026‑17106, a Docker cp race‑condition that allows arbitrary host file overwrite; technical analysis and PoC are published, but no evidence of in‑the‑wild exploitation exists, and a patch is available for affected versions.
kokumօtօ[verified]@__kokumotoPoC
The post explains CVE-2026-17106 (CopyEscape), detailing how a crafted tar payload in docker cp can write arbitrary files to the host, and links to a blog containing a proof‑of‑concept.
Christian Lempa[verified]@ChristianLempaPatch
The alert announces the CVE-2026-17106 vulnerability affecting Docker cp, provides remedial version updates, and links to related advisory documentation.