PT-2026-108794 · Red Hat · Red Hat Build Of Podman Desktop+9

·

CVE-2026-107935

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

9.3

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107935

Affected Products

Red Hat Build Of Podman Desktop
Red Hat Certification Program For Red Hat Enterprise Linux 9
Red Hat Edge Manager 1
Red Hat Enterprise Linux 10
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9
Red Hat Hardened Images
Red Hat Openshift Container Platform 4
Red Hat Openshift Dev Spaces
Red Hat Openstack Platform 18.0