CVE-2026-61801 — The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files.
Description
The `github.com/moby/sys/user` package provides Go utilities for parsing and looking up entries in Unix-style user and group database files. Versions before 0.4.1 do not sufficiently limit entries when parsing `/etc/passwd`- or `/etc/group`-style files, allowing an attacker who can supply a specially crafted file to cause excessive memory consumption and potentially terminate the affected process due to an out-of-memory condition. This issue is patched in version 0.4.1. As a workaround, avoid parsing attacker-controlled user or group database files, or validate and limit untrusted input before parsing it.
CVSS v3.1 base metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
Affected
- Vendor
- Go
- Product
- github.com/moby/sys/user
Versions
- pkg:golang/github.com/moby/sys/user < 0.4.1
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/moby/sys/commit/85a71bbe1faa36c552a960e6a5f3d0cfb632fbbe
- advisory[email protected]https://github.com/moby/sys/pull/221
- advisory[email protected]https://github.com/moby/sys/security/advisories/GHSA-mjcv-p78q-w5fw
- advisoryOSV GHSA-mjcv-p78q-w5fwhttps://osv.dev/vulnerability/GHSA-mjcv-p78q-w5fw
- vendorOSV packagehttps://github.com/moby/sys
Related threats
same CWE or vendorCVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107392 · 3h ago
CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107391 · 3h ago
CVE-2026-95209 — An issue in gnutls v3.8.13 causes legitimate CA certificates to be rejected, leading to a Denial of Service (DoS).
CVE-2026-95209 · 4h ago
CVE-2026-84276 — IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller.
CVE-2026-84276 · 4h ago
CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 4h ago
CVE-2026-95184 — Improper certificate validation in gnutls v3.8.13 causes the application to reject legitimate certificates for valid users, leading to a Denial of …
CVE-2026-95184 · 5h ago