๐Ÿ” CVE Alert

CVE-2026-107935

CRITICAL 9.3

Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose

CVSS Score
9.3
EPSS Score
0.0%
EPSS Percentile
0th

A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.

CWE CWE-22
Vendor red hat
Product red hat build of podman desktop
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat build of podman desktop

Be the first to know when new critical vulnerabilities affecting red hat red hat build of podman desktop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
High
Availability
High

Affected Versions

Red Hat / Red Hat Build of Podman Desktop
All versions affected
Red Hat / Red Hat Certification Program for Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Edge Manager 1
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 10
All versions affected
Red Hat / Red Hat Enterprise Linux 8
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Enterprise Linux 9
All versions affected
Red Hat / Red Hat Hardened Images
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Dev Spaces
All versions affected
Red Hat / Red Hat OpenStack Platform 18.0
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-107935 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2548382 github.com: https://github.com/containers/gvisor-tap-vsock/pull/718 redhat.atlassian.net: https://redhat.atlassian.net/browse/RHDESK-550

Credits

This issue was discovered by Lucas Celant (Red Hat).