Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-5116"
}