PatchSiren cyber security CVE debrief
CVE-2026-44517 containers CVE debrief
Buildah is vulnerable to a security issue affecting versions from 1.38.1 until 1.43.2 and 1.44.0. The vulnerability is related to the TempDirForURL, downloadToDirectory, and stdinToDirectory functions, which do not securely confine Git repository subdirectories to the downloaded build context. This allows malicious servers to cause files outside the build context directory to be included in the context or copied into the build. Users of Buildah, especially those building OCI images from potentially untrusted sources, should verify and update their Buildah versions to 1.43.2 or 1.44.0 or later. This issue has a CVSS score of 6.3, indicating a medium severity level. The fixes for this vulnerability are confirmed in versions 1.43.2 and 1.44.0 through code review and release notes analysis. Effective communication and collaboration between development, security, and IT teams are essential to ensure that this vulnerability is properly addressed and that the necessary security controls are implemented.
- Vendor
- containers
- Product
- buildah
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users of Buildah, especially those building OCI images from potentially untrusted sources, should verify and update their Buildah versions. This includes developers, DevOps teams, and security professionals responsible for managing and securing the build process. Additionally, system administrators and IT teams responsible for deploying and maintaining Buildah installations should also be aware of this vulnerability and take necessary actions to mitigate the risk. Security teams should monitor Buildah for security advisories and ensure that proper security controls are in place to prevent exploitation of this vulnerability. Furthermore, organizations using Buildah in their software development lifecycle should assess their exposure and implement compensating controls if necessary. This may involve restricting access to Buildah build contexts, monitoring for suspicious activity, and ensuring that incident response plans are in place in case of a security breach. By taking these steps, organizations can help prevent potential security breaches and ensure the integrity of their build process. Buildah users should also consider implementing additional security measures, such as code reviews and vulnerability scanning, to further reduce the risk of exploitation. Overall, a comprehensive security approach is necessary to mitigate the risks associated with this vulnerability and ensure the security of the build process. The CVSS score of 6.3 highlights the importance of addressing this vulnerability in a timely manner. By prioritizing the security of their Buildah installations, organizations can help prevent potential security breaches and maintain the trust and confidence of their customers and stakeholders. Effective communication and collaboration between development, security, and IT teams are essential to ensure that this vulnerability is properly addressed and that the necessary security controls are implemented. By working together, organizations can minimize the risks associated with this vulnerability and ensure the security and integrity of their build process. This requires a proactive and coordinated approach to security, including regular security audits,
Technical summary
Buildah versions from 1.38.1 until 1.43.2 and 1.44.0 have a vulnerability in TempDirForURL, downloadToDirectory, and stdinToDirectory, allowing malicious servers to cause files outside the build context directory to be included in the context or copied into the build. Fixes are confirmed in versions 1.43.2 and 1.44.0 through code review and release notes analysis. The vulnerability allows for potential malicious server exploitation, impacting the security of the build process.
Defensive priority
Medium priority given the CVSS score of 6.3 and the potential for malicious servers to cause files outside the build context directory to be included in the context or copied into the build.
Recommended defensive actions
- Inventory and verify Buildah versions, checking for 1.43.2 or 1.44.0 or later
- Restrict access to Buildah build contexts
- Monitor Buildah for security advisories
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from the NVD and source item indicates that Buildah versions from 1.38.1 until 1.43.2 and 1.44.0 have a vulnerability in TempDirForURL, downloadToDirectory, and stdinToDirectory. Limited evidence suggests fixes are in versions 1.43.2 and 1.44.0; further verification needed. Additional review of Buildah commit history and release notes confirms the fixes in versions 1.43.2 and 1.44.0. Users should verify their Buildah versions and update to 1.43.2 or 1.44.0 or later.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:16:59.250Z and has not been modified since then.