18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/containers/buildah is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.6
CVE-2024-11218
Buildah allows build breakout using malicious Containerfiles and concurrent builds
MEDIUM 4.7
CVE-2024-9407
Improper Input Validation in Buildah and Podman
MEDIUM 4.4
CVE-2024-9675
Buildah allows arbitrary directory mount
UNKNOWN
CVE-2024-1753
Container escape at build time
HIGH 7.1
CVE-2022-2990
Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification
HIGH 8.8
CVE-2020-10696
Path Traversal in Buildah
MEDIUM 6.8
CVE-2022-27651
Non-empty default inheritable capabilities for linux container in Buildah
MEDIUM 5.5
CVE-2021-3602
Buildah processes using chroot isolation may leak environment values to intermediate processes
MEDIUM 6.3
CVE-2026-44517
Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive
UNKNOWN
CVE-2026-44517
Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah
UNKNOWN
CVE-2021-3602
Environment variable leakage in github.com/containers/buildah
UNKNOWN
CVE-2022-2990
Unauthorized file access in github.com/containers/buildah
UNKNOWN
CVE-2020-10696
Path Traversal in Buildah in github.com/containers/buildah
UNKNOWN
CVE-2024-9407
Improper Input Validation in Buildah and Podman in github.com/containers/buildah
UNKNOWN
CVE-2022-27651
Incorrect default permissions in github.com/containers/buildah
UNKNOWN
CVE-2024-9675
Buildah allows arbitrary directory mount in github.com/containers/buildah
UNKNOWN
CVE-2024-11218
Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah
UNKNOWN
CVE-2024-1753
Container escape at build time in github.com/containers/buildah
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes