Podman · Podman · CVE-2026-57231
**Name of the Vulnerable Software and Affected Versions**
Podman versions 1.8.1 through 5.8.4
**Description**
A malicious container image can trick Podman into leaking host environment variables into the container. This occurs when an image contains an `Env` entry consisting of a key without a value. Furthermore, using an asterisk (`*`) as a glob operator allows the exfiltration of all environment variables set in the session from which the container is launched, even if their exact names are unknown.
**Recommendations**
Update Podman to version 5.8.4 or 6.0.0.