{"id":"GO-2026-5116","summary":"Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah","details":"Buildah allows a build-time breakout when using a malicious Containerfile or a malicious Git HTTP server. A crafted Git URL or Containerfile can cause Buildah to access files outside of the build context during an ADD or COPY operation.","aliases":["CVE-2026-44517","GHSA-49p4-px3h-rq49"],"modified":"2026-07-27T17:00:20.108518126Z","published":"2026-07-27T15:30:50Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5116","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/containers/buildah/security/advisories/GHSA-49p4-px3h-rq49"}],"affected":[{"package":{"name":"github.com/containers/buildah","ecosystem":"Go","purl":"pkg:golang/github.com/containers/buildah"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.38.1"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5116.json"}}],"schema_version":"1.7.5"}