Allocation of Resources Without Limits or Throttling in OpenBao - CVE-2026-39396
Published: April 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in ExtractPluginFromImage() in the OCI plugin downloader when extracting a plugin binary from a container image. A remote attacker can serve a crafted OCI image containing a decompression bomb to cause a denial of service.
User interaction is required to trigger plugin loading, such as starting OpenBao or reloading its configuration, and instances with automatic plugin download enabled can be repeatedly affected on restart or reload.
Affected software
Fedora
openbao
How to mitigate CVE-2026-39396
openbao - addressed in versions 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in Jupyter Notebook
- Fedora EPEL 8 update for openbao
- Fedora EPEL 10.3 update for openbao
- Fedora 43 update for openbao
- Fedora EPEL 10.1 update for openbao
- Fedora 44 update for openbao
- Fedora 42 update for openbao
- Fedora EPEL 10.2 update for openbao
- Fedora EPEL 9 update for openbao