PT-2026-33882 · Openbao+1 · Openbao+1

·

CVE-2026-39396

·

Published

2026-04-20

·

Updated

2026-07-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.3
Description The OCI plugin downloader contains an issue in the ExtractPluginFromImage() function where plugin binaries are extracted from container images by streaming decompressed tar data via io.Copy without a limit on the number of bytes written. An attacker controlling or compromising the OCI registry can provide a crafted image containing a decompression bomb—a file that expands to an arbitrarily large size upon decompression—leading to disk exhaustion. Because the SHA256 integrity check is performed only after the file is fully written to disk, the hash mismatch is detected too late to prevent the impact. This allows an attacker to replace a legitimate plugin image without needing to alter its signature.
Recommendations Update to version 2.5.3.

Exploit

Fix

DoS

Uncontrolled Recursion

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08728
BIT-OPENBAO-2026-39396
CVE-2026-39396
GHSA-R65V-XGWC-G56J
GO-2026-5609
OPENSUSE-SU-2026:10594-1
OPENSUSE-SU-2026:21483-1

Affected Products

Openbao
Red Os