{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/kraken--0.1.29/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:uber:kraken:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92791"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kraken (\u003c= 0.1.29)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["Uber"],"content_html":"\u003cp\u003eUber Kraken versions 0.1.29 and earlier are affected by a path traversal vulnerability tracked as CVE-2026-92791. The issue resides in the /tags/{tag} API endpoint, which fails to properly validate the tag parameter before using it in file system operations. An unauthenticated attacker can exploit this flaw by submitting percent-encoded parent-directory sequences, such as %2e%2e%2f, within the tag parameter. This allows the attacker to traverse outside the designated storage root and access sensitive files on the underlying host that are readable by the testfs backend process. This vulnerability poses a significant risk to confidentiality, potentially exposing configuration files, secrets, or system data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary files on the host system, potentially leading to information disclosure, unauthorized access to credentials, or further compromise of the infrastructure supporting the Kraken container registry service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Uber Kraken to a version beyond 0.1.29 immediately to remediate CVE-2026-92791.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the /tags/{tag} endpoint for indicators of path traversal attempts, specifically looking for URL-encoded dot-dot-slash patterns.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to block requests containing percent-encoded parent directory traversal sequences targeting the /tags/ endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:57:10Z","date_published":"2026-09-16T21:57:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-uber-kraken-path-traversal/","summary":"Uber Kraken versions 0.1.29 and earlier contain a path traversal vulnerability in the /tags/{tag} endpoint, allowing unauthenticated attackers to read arbitrary files from the filesystem.","title":"Path Traversal in Uber Kraken","url":"https://feed.craftedsignal.io/briefs/2026-09-uber-kraken-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Kraken (\u003c= 0.1.29)","version":"https://jsonfeed.org/version/1.1"}