CVE-2023-22970: Fedoraproject Fedora
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Affected products
- Fedoraproject Fedora: version 37 only; version 38 only
- Usebottles Bottles: before 51.0 (fixed in 51.0)
Published 2023-05-26. Last modified 2026-06-17.