
CVE-2026-39396: CVE-2026-39396: Resource Exhaustion via Decompression Bomb in OpenBao OCI Plugin Downloader OpenBao versions prior to 2.5.3 are vulnerable to a resource exhaustion denial-of-service (DoS) flaw due to unbounded disk writes during OCI pl... https://cvereports.com/reports/CVE-2026-39396
Post summary
The report discloses a resource exhaustion denial‑of‑service vulnerability in OpenBao versions before 2.5.3, but includes no PoC, exploit, or active exploitation claims and does not mention any patch or workaround.

