CVE-2026-107935: Red Hat Build Of Podman Desktop
Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
Affected products
- Red Hat Red Hat Build Of Podman Desktop
- Red Hat Red Hat Certification Program For Red Hat Enterprise Linux 9
- Red Hat Red Hat Edge Manager 1
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Hardened Images
- Red Hat Red Hat Openshift Container Platform 4
- Red Hat Red Hat Openshift Dev Spaces
- Red Hat Red Hat Openstack Platform 18.0
Published 2026-10-09. Last modified 2026-10-09.