Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.36% | — | PodmanAI | 15/9/2026 | 29/9/2026 | A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman. | |
| Pendiente de análisis | Media (4.2) | 0.16% | — | PodmanAI | 13/8/2026 | 22/9/2026 | The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS configurations), the fallback in ReflinkOrCopy uses io.Copy which performs… | |
| Analizada | Alta (7.5) | 0.44% | — | Podman Project Podman | 26/6/2026 | 6/7/2026 | Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to… | |
| Analizada | Media (5.3) | 0.40% | — | Podman Project Podman | 26/6/2026 | 26/6/2026 | Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious… | |
| Modificada | Media (4) | 0.68% | — | Podman Project Podman | 14/4/2026 | 24/7/2026 | Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression… | |
| Modificada | Crítica (9.1) | 0.73% | — | Linuxfoundation Podman Desktop | 7/4/2026 | 24/7/2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an… | |
| Analizada | Alta (8.8) | 0.31% | — | Linuxfoundation Podman Desktop | 28/1/2026 | 17/6/2026 | Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `isAccessAllowed()`… | |
| Aplazada | Alta (8.4) | 0.74% | — | PodmanAICbis ManagerAI | 18/9/2025 | 17/6/2026 | The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation,… | |
| Aplazada | Alta (8.8) | 0.42% | — | Cbis NCS ManagerAINginxAIPodmanAI | 18/9/2025 | 17/6/2026 | The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functions. This flaw allows attackers to reach restricted or sensitive endpoints of the HTTP API without providing any valid credentials. The root… | |
| Aplazada | Alta (7.4) | 0.64% | — | PodmanAI | 16/9/2025 | 1/9/2026 | A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible. | |
| Aplazada | Alta (8.1) | 1.1% | — | PodmanAI | 5/9/2025 | 28/9/2026 | There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be… | |
| Aplazada | Alta (8.3) | 0.52% | — | PodmanAI | 24/6/2025 | 31/8/2026 | A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack. | |
| Aplazada | Alta (8.6) | 0.36% | — | PodmanAIContainers BuildahAI | 22/1/2025 | 31/8/2026 | A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host. | |
| Modificada | Media (4.8) | 0.55% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 2/8/2024 | 17/6/2026 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is… | |
| Aplazada | Alta (8.6) | 0.49% | — | BuildahAIPodmanAI | 18/3/2024 | 25/9/2026 | A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the root filesystem as a mount source and cause the mount operation to mount the host… | |
| Modificada | Media (6.8) | 0.54% | — | Podman Project PodmanRedhat Enterprise Linux | 27/3/2023 | 17/6/2026 | A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system. | |
| Modificada | Baja (3.3) | 0.24% | — | Podman Project PodmanFedoraproject Fedora | 8/12/2022 | 17/6/2026 | A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. | |
| Modificada | Media (5.3) | 0.83% | — | Podman Project PodmanFedoraproject Fedora | 8/12/2022 | 17/6/2026 | A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure. | |
| Modificada | Alta (7.1) | 0.32% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux | 13/9/2022 | 17/6/2026 | An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code… | |
| Modificada | Media (5.3) | 0.51% | — | Redhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationPodman Project Podman | 1/9/2022 | 17/6/2026 | The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in… | |
| Modificada | Alta (7.5) | 0.91% | — | Redhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationPodman Project Podman | 1/9/2022 | 17/6/2026 | The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications… | |
| Modificada | Alta (8.8) | 2.6% | — | Podman Project PodmanVarlink | 9/6/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Podman and Varlink 1.5.1. This affects an unknown part of the component API. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Alta (8.8) | 4.2% | — | Podman Project PodmanPsgo Project PsgoRedhat Developer ToolsRedhat Enterprise Linux Server Update Services FOR SAP Solutions+12 | 29/4/2022 | 17/6/2026 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem,… | |
| Modificada | Alta (7.5) | 1.4% | — | Podman Project PodmanRedhat Developer ToolsRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/4/2022 | 17/6/2026 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with… | |
| Modificada | Media (6.5) | 1.1% | — | Podman Project PodmanFedoraproject FedoraRedhat Enterprise Linux | 23/12/2021 | 17/6/2026 | A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker… |