CVE-2026-39396Disclosure(openbao / openbao)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openbao openbao systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a plugin binary from a container image by streaming decompressed tar data via `io.Copy` with no upper bound on the number of bytes written. An attacker who controls or compromises the OCI registry referenced in the victim's configuration can serve a crafted image containing a decompression bomb that decompresses to an arbitrarily large file. The SHA256 integrity check occurs after the full file is written to disk, meaning the hash mismatch is detected only after the damage (disk exhaustion) has already occurred. This allow the attacker to replace **legit plugin image** with no need to change its signature. Version 2.5.3 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-674CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openbao

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-04-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openbao

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-28: 104-2104-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39396: CVE-2026-39396: Resource Exhaustion via Decompression Bomb in OpenBao OCI Plugin Downloader OpenBao versions prior to 2.5.3 are vulnerable to a resource exhaustion denial-of-service (DoS) flaw due to unbounded disk writes during OCI pl... https://cvereports.com/reports/CVE-2026-39396

    Post summary

    The report discloses a resource exhaustion denial‑of‑service vulnerability in OpenBao versions before 2.5.3, but includes no PoC, exploit, or active exploitation claims and does not mention any patch or workaround.

    0000034
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39396 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.3, `ExtractPluginFromImage()` in OpenBao's OCI plugin downloader extracts a p… https://www.cve.org/CVERecord?id=CVE-2026-39396

    Post summary

    The snippet discloses CVE‑2026‑39396 affecting OpenBao’s OCI plugin downloader, noting that the issue exists before version 2.5.3 and implying a patch is available in that release.

    0000090
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenbaoopenbao---

Explore more