GHSA-49p4-px3h-rq49

Suggest an improvement
Source
https://github.com/advisories/GHSA-49p4-px3h-rq49
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-49p4-px3h-rq49/GHSA-49p4-px3h-rq49.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-49p4-px3h-rq49
Aliases
  • CVE-2026-44517
Published
2026-06-22T20:15:48Z
Modified
2026-06-22T20:30:08.093479918Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
Details

Impact

When processing a build contexts or add/copy instructions, a malicious server serving a Git repository or a tar archive file can cause files outside of the build context directory to be included in the build context or copied into the build.

Patches

Fixed in Buildah 1.44 and 1.43.2.

Database specific
{
    "github_reviewed_at": "2026-06-22T20:15:48Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "nvd_published_at": null
}
References

Affected packages

Go / github.com/containers/buildah

Package

Name
github.com/containers/buildah
View open source insights on deps.dev
Purl
pkg:golang/github.com/containers/buildah

Affected ranges

Type
SEMVER
Events
Introduced
1.38.1
Fixed
1.43.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-49p4-px3h-rq49/GHSA-49p4-px3h-rq49.json"