go

github.com/containers/buildah

View on go registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/containers/buildah is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.6
Go

CVE-2024-11218

Buildah allows build breakout using malicious Containerfiles and concurrent builds

MEDIUM 4.7
Go

CVE-2024-9407

Improper Input Validation in Buildah and Podman

MEDIUM 4.4
Go

CVE-2024-9675

Buildah allows arbitrary directory mount

UNKNOWN
Go

CVE-2024-1753

Container escape at build time

HIGH 7.1
Go

CVE-2022-2990

Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification

HIGH 8.8
Go

CVE-2020-10696

Path Traversal in Buildah

MEDIUM 6.8
Go

CVE-2022-27651

Non-empty default inheritable capabilities for linux container in Buildah

MEDIUM 5.5
Go

CVE-2021-3602

Buildah processes using chroot isolation may leak environment values to intermediate processes

MEDIUM 6.3
Go

CVE-2026-44517

Build breakout using malicious Containerfile and Git Smart HTTP server or GitHub release tar archive

UNKNOWN
Go

CVE-2026-44517

Build breakout using malicious Containerfile or Git HTTP server in github.com/containers/buildah

UNKNOWN
Go

CVE-2021-3602

Environment variable leakage in github.com/containers/buildah

UNKNOWN
Go

CVE-2022-2990

Unauthorized file access in github.com/containers/buildah

UNKNOWN
Go

CVE-2020-10696

Path Traversal in Buildah in github.com/containers/buildah

UNKNOWN
Go

CVE-2024-9407

Improper Input Validation in Buildah and Podman in github.com/containers/buildah

UNKNOWN
Go

CVE-2022-27651

Incorrect default permissions in github.com/containers/buildah

UNKNOWN
Go

CVE-2024-9675

Buildah allows arbitrary directory mount in github.com/containers/buildah

UNKNOWN
Go

CVE-2024-11218

Buildah allows build breakout using malicious Containerfiles and concurrent builds in github.com/containers/buildah

UNKNOWN
Go

CVE-2024-1753

Container escape at build time in github.com/containers/buildah

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes