Known vulnerabilities in buildah

Software: buildah
Software CPE: cpe:2.3:a:containers:buildah:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting buildah buildah is affected by 21 known vulnerabilities: 3 high, 7 medium, 11 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118717 - Improper input validation
CVE-2025-47913
CWE-20 Low
No
No
1.41.8 24.11.2025 SB2025112448
SB2025112455
SB2025112456
and 53 more
#VU118106 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52565
CWE-61 Low
No
No
1.33.14 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 38 more
#VU118105 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52881
CWE-61 Low
No
No
1.33.14, 1.37.8 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 62 more
#VU118104 - UNIX Symbolic Link (Symlink) Following
CVE-2025-31133
CWE-61 Low
Available
No
1.33.14 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 34 more
#VU112114 - Type confusion
CVE-2025-49713
CWE-843 High
No
No
1.33.14, 1.37.8, 1.39.8 02.07.2025 SB2025070289
SB2026011330
SB2026011331
and 1 more
#VU103500 - Permissions, Privileges, and Access Controls
CVE-2024-11218
CWE-264 Medium
No
No
1.26.9, 1.27.6, 1.33.12, 1.35.5, 1.37.6, 1.38.1 03.02.2025 SB2025020321
SB2025020332
SB2025020333
and 34 more
#VU98828 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-9675
CWE-22 Low
No
No
1.29.4, 1.37.5 21.10.2024 SB2024102103
SB2024102104
SB2024102107
and 51 more
#VU98817 - UNIX Symbolic Link (Symlink) Following
CVE-2024-9676
CWE-61 Low
No
No
1.37.5 18.10.2024 SB2024101822
SB2024101823
SB2024101824
and 49 more
#VU98141 - Improper input validation
CVE-2024-9341
CWE-20 Low
No
No
1.37.4 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 44 more
#VU98140 - Improper input validation
CVE-2024-9407
CWE-20 Low
No
No
1.37.4 08.10.2024 SB2024100842
SB2024100843
SB2024100848
and 24 more
#VU89685 - Improper Validation of Integrity Check Value
CVE-2024-3727
CWE-354 Medium
No
No
1.33.8 21.05.2024 SB2024052112
SB2024052116
SB2024052117
and 68 more
#VU87616 - Improper Privilege Management
CVE-2024-1753
CWE-269 High
No
No
1.24.7, 1.26.7, 1.34.2, 1.35.1, 1.27.4, 1.29.3, 1.32.3, 1.33.8 19.03.2024 SB2024031925
SB2024032051
SB2024032613
and 41 more
#VU87538 - Resource exhaustion
CVE-2024-28180
CWE-400 Medium
No
No
1.33.8 14.03.2024 SB2024031446
SB2024031447
SB2024031448
and 106 more
#VU87326 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2024-24786
CWE-835 Medium
No
No
1.27.4, 1.29.3, 1.32.3 11.03.2024 SB2024031115
SB2024031435
SB2024031555
and 134 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
1.32.0, 1.32.1, 1.32.2 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU69291 - Incorrect Authorization
CVE-2022-2990
CWE-863 Low
No
No
1.27.1 14.11.2022 SB2022111431
SB2022111435
SB2022111439
and 14 more
#VU61797 - Incorrect Default Permissions
CVE-2022-27651
CWE-276 Medium
No
No
1.24.3, 1.25.0, 1.23.4 01.04.2022 SB2022040108
SB2022040807
SB2022042012
and 14 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
1.23.4 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more
#VU54940 - Exposure of sensitive information to an unauthorized actor
CVE-2021-3602
CWE-200 Low
No
No
1.16.8, 1.17.2, 1.19.9, 1.21.3 19.07.2021 SB2021071902
SB2021072007
SB2022092037
and 7 more
#VU26643 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-10696
CWE-22 High
No
No
1.14.4 07.04.2020 SB2020040723
SB2020042905
SB2020043013
and 12 more


Showing elements 1 - 20 out of 21