CVE-2026-92791
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
16/09/2026
Last modified:
24/09/2026
Description
Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments in the tag parameter to read arbitrary files accessible to the testfs backend process.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/uber/kraken
- https://github.com/uber/kraken/blob/v0.1.27/build-index/tagserver/server.go#L128-L129
- https://github.com/uber/kraken/blob/v0.1.27/lib/backend/namepath/pather.go#L78-L84
- https://github.com/uber/kraken/blob/v0.1.27/lib/backend/testfs/server.go#L165-L173
- https://github.com/uber/kraken/issues/645
- https://www.vulncheck.com/advisories/uber-kraken-through-0.1.29-path-traversal-via-tag-parameter
- https://github.com/uber/kraken/issues/645


