Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39396

23
FAUCET Score

OVERVIEW CVE-2026-39396 is a decompression bomb vulnerability affecting OpenBao, an open source identity-based secrets management system, in versions prior to 2.5.3. The vulnerability exists in the ExtractPluginFromImage() function of OpenBao's OCI plugin downloader, which processes container images without imposing size limits during decompression. An attacker controlling or compromising the OCI registry can serve a malicious container image that decompresses to an arbitrarily large file, causing disk exhaustion on the victim's system. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.1 (LOW) with a network-based attack vector and high attack complexity that requires user interaction. The impact is limited to availability, with no confidentiality or integrity concerns from the vulnerability itself. However, a critical aspect of this flaw is that the SHA256 integrity check occurs only after the entire file is written to disk, meaning the hash mismatch is detected post-exploitation. This allows attackers to replace legitimate plugin images without modifying signatures, creating a deceptive attack scenario. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the absence of this CVE from CISA's Known Exploited Vulnerabilities catalog and its inactive status on threat tracking platforms. The EPSS score of 0.00033 indicates minimal likelihood of exploitation compared to other known vulnerabilities. A patch is available in OpenBao version 2.5.3, and the combination of high attack complexity and low severity suggests community attention has been minimal.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.3CPE matchmatch criteria
cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 12th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/openbao/openbaoFixed in: 0.0.0-20260420180337-2b2a901aa9f7
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-r65v-xgwc-g56jlow

OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)

Apr 21, 2026

References

github.com / openbao/openbao/security/advisories/GHSA-r65v-xgwc-g56j
ExploitVendor Advisory