{"id":"ECHO-7ce4-b04c-827e","upstream":["CVE-2026-17106","GHSA-hfg8-hc9c-6c3h"],"severity":[],"modified":"2026-09-28T00:01:25.968Z","affected":[{"package":{"ecosystem":"Echo:Go","name":"github.com/moby/go-archive","purl":"pkg:golang/github.com/moby/go-archive"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-17106"},{"type":"WEB","url":"https://github.com/advisories/GHSA-hfg8-hc9c-6c3h"}]}