๐Ÿ” CVE Alert

CVE-2026-61801

MEDIUM 5.5

github.com/moby/sys/user has a possible DoS via unbounded parsing of user and group database files

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.

CWE CWE-400
Vendor moby
Product sys
Published Oct 8, 2026
Last Updated Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for moby sys

Be the first to know when new medium vulnerabilities affecting moby sys are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

moby / sys
< 0.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw github.com: https://github.com/moby/sys/pull/221 github.com: https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe