CVE-2026-107935: Red Hat Build Of Podman Desktop

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.

Affected products

  • Red Hat Red Hat Build Of Podman Desktop
  • Red Hat Red Hat Certification Program For Red Hat Enterprise Linux 9
  • Red Hat Red Hat Edge Manager 1
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Hardened Images
  • Red Hat Red Hat Openshift Container Platform 4
  • Red Hat Red Hat Openshift Dev Spaces
  • Red Hat Red Hat Openstack Platform 18.0

Published 2026-10-09. Last modified 2026-10-09.