Arbitrary File Inclusion in Buildah by Podman Container Tools
CVE-2026-44517

6.3MEDIUM

Key Information:

Vendor

Containers

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-44517?

Buildah, a tool designed for building OCI images, has a vulnerability that allows a malicious server to exploit the TempDirForURL function, failing to appropriately isolate Git repository subdirectories from the downloaded build context. This flaw can enable the inclusion of files from outside the intended directory during the build process, posing a significant risk when handling Git repositories or tar archives. The issues are addressed in versions 1.43.2 and 1.44.0, correcting the insecure handling that previously opened avenues for exploitation.

Affected Version(s)

buildah >= 1.38.1, < 1.43.2

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.