VDB
KO

GO-2026-5116

Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah

Details

Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/containers/buildah
Introduced in: 1.38.1

No fixed version published yet for github.com/containers/buildah (go modules). Pin to a known-safe version or switch to an alternative.

References