OpenBao Secrets Management System Vulnerability in OCI Plugin Downloader
CVE-2026-39396

3.1LOW

Key Information:

Vendor

Openbao

Status
Vendor
CVE Published:
21 April 2026

What is CVE-2026-39396?

The OpenBao identity-based secrets management system contains a vulnerability in the OCI plugin downloader. Prior to version 2.5.3, the method ExtractPluginFromImage() allows an attacker to potentially drain disk storage by streaming decompressed content without restrictions. An attacker controlling an OCI registry can serve a maliciously crafted image that decompresses to an excessively large file, leading to disk exhaustion. Since the SHA256 integrity check occurs post-write, the system fails to detect issues before significant damages occur, allowing unauthorized modifications to plugin images without altering their signatures. The vulnerability is addressed in version 2.5.3 with appropriate safeguards.

Affected Version(s)

openbao < 2.5.3

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.