—
GO-2026-5116
Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah
Details
Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/containers/buildah
Introduced in:
1.38.1 No fixed version published yet for github.com/containers/buildah (go modules). Pin to a known-safe version or switch to an alternative.