OpenBao Secrets Management System Vulnerability in OCI Plugin Downloader
CVE-2026-39396
3.1LOW
What is CVE-2026-39396?
The OpenBao identity-based secrets management system contains a vulnerability in the OCI plugin downloader. Prior to version 2.5.3, the method ExtractPluginFromImage() allows an attacker to potentially drain disk storage by streaming decompressed content without restrictions. An attacker controlling an OCI registry can serve a maliciously crafted image that decompresses to an excessively large file, leading to disk exhaustion. Since the SHA256 integrity check occurs post-write, the system fails to detect issues before significant damages occur, allowing unauthorized modifications to plugin images without altering their signatures. The vulnerability is addressed in version 2.5.3 with appropriate safeguards.
Affected Version(s)
openbao < 2.5.3
