OVERVIEW CVE-2026-39396 is a decompression bomb vulnerability affecting OpenBao, an open source identity-based secrets management system, in versions prior to 2.5.3. The vulnerability exists in the ExtractPluginFromImage() function of OpenBao's OCI plugin downloader, which processes container images without imposing size limits during decompression. An attacker controlling or compromising the OCI registry can serve a malicious container image that decompresses to an arbitrarily large file, causing disk exhaustion on the victim's system. SEVERITY The vulnerability carries a CVSS v3.1 score of 3.1 (LOW) with a network-based attack vector and high attack complexity that requires user interaction. The impact is limited to availability, with no confidentiality or integrity concerns from the vulnerability itself. However, a critical aspect of this flaw is that the SHA256 integrity check occurs only after the entire file is written to disk, meaning the hash mismatch is detected post-exploitation. This allows attackers to replace legitimate plugin images without modifying signatures, creating a deceptive attack scenario. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the absence of this CVE from CISA's Known Exploited Vulnerabilities catalog and its inactive status on threat tracking platforms. The EPSS score of 0.00033 indicates minimal likelihood of exploitation compared to other known vulnerabilities. A patch is available in OpenBao version 2.5.3, and the combination of high attack complexity and low severity suggests community attention has been minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.3CPE matchmatch criteria | cpe:2.3:a:openbao:openbao:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.