Medium severityNVD Advisory· Published Jun 22, 2026
Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
CVE-2026-44517
Description
Impact
When processing a build contexts or add/copy instructions, a malicious server serving a Git repository or a tar archive file can cause files outside of the build context directory to be included in the build context or copied into the build.
Patches
Fixed in Buildah 1.44 and 1.43.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/containers/buildahGo | >= 1.38.1, < 1.43.2 | 1.43.2 |
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.