Allocation of Resources Without Limits or Throttling in OpenBao - CVE-2026-39396

 

Allocation of Resources Without Limits or Throttling in OpenBao - CVE-2026-39396

Published: April 21, 2026


Vulnerability identifier: #VU126701
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-39396
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in ExtractPluginFromImage() in the OCI plugin downloader when extracting a plugin binary from a container image. A remote attacker can serve a crafted OCI image containing a decompression bomb to cause a denial of service.

User interaction is required to trigger plugin loading, such as starting OpenBao or reloading its configuration, and instances with automatic plugin download enabled can be repeatedly affected on restart or reload.


Affected software

OpenBao
Fedora
openbao

How to mitigate CVE-2026-39396

Install security update from vendor's website.

OpenBao - update to 2.5.3
openbao - addressed in versions 2.5.3-1.el8, 2.5.3-1.el9, 2.5.3-1.el10_1, 2.5.3-1.el10_2, 2.5.3-1.el10_3, 2.5.3-1.fc42, 2.5.3-1.fc43, 2.5.3-1.fc44

External References

Related Security Bulletins