PT-2026-33882 · Openbao+1 · Openbao+1

N1Rwhex

·

Published

2026-04-21

·

Updated

2026-05-27

·

CVE-2026-39396

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenBao versions prior to 2.5.3
Description The OCI plugin downloader contains an issue in the ExtractPluginFromImage() function where plugin binaries are extracted from container images by streaming decompressed tar data via io.Copy without a limit on the number of bytes written. An attacker controlling or compromising the OCI registry can provide a crafted image containing a decompression bomb—a file that expands to an arbitrarily large size upon decompression—leading to disk exhaustion. Because the SHA256 integrity check is performed only after the file is fully written to disk, the hash mismatch is detected too late to prevent the impact. This allows an attacker to replace a legitimate plugin image without needing to alter its signature.
Recommendations Update to version 2.5.3.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39396
GHSA-R65V-XGWC-G56J
OPENSUSE-SU-2026:10594-1

Affected Products

Openbao
Red Os