Arbitrary File Inclusion in Buildah by Podman Container Tools
CVE-2026-44517
6.3MEDIUM
What is CVE-2026-44517?
Buildah, a tool designed for building OCI images, has a vulnerability that allows a malicious server to exploit the TempDirForURL function, failing to appropriately isolate Git repository subdirectories from the downloaded build context. This flaw can enable the inclusion of files from outside the intended directory during the build process, posing a significant risk when handling Git repositories or tar archives. The issues are addressed in versions 1.43.2 and 1.44.0, correcting the insecure handling that previously opened avenues for exploitation.
Affected Version(s)
buildah >= 1.38.1, < 1.43.2
