Moby version 25.0.18 fixes CVE-2026-17106, in which a crafted tar archive can write outside the extraction directory. The fix is included in the Moby release.
A flaw that allows crafted archives to write outside an extraction directory poses a security risk to Moby users. The release supplies a fix for the identified vulnerability.