{"id":"CVE-2025-6032","title":"A flaw was found in Podman","summary":"A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.","severity":"high","cvss":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-295"],"published":"2025-06-24","updated":"2026-06-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-6032","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:10295","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10549","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10550","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10551","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:10668","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11359","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11363","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11677","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:11681","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:15397","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9726","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9751","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:9766","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-6032","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2372501","label":"secalert@redhat.com"},{"url":"https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3","label":"secalert@redhat.com"},{"url":"https://github.com/containers/podman/security/advisories/GHSA-65gg-3w2w-hr4h","label":"secalert@redhat.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6032"},{"url":"https://github.com/containers/podman"}],"tags":["nvd","osv","go"],"epss":0.00479,"epssPercentile":0.40537,"ingestedAt":"2026-06-29T13:24:34.383Z","aliases":["GHSA-65gg-3w2w-hr4h","GO-2025-3777"],"ecosystem":"go","vendor":"containers","product":"github.com/containers/podman/v4","affected":["github.com/containers/podman/v4 >= 4.8.0, <= 4.9.5","github.com/containers/podman/v5 < 5.5.2"],"patched":["github.com/containers/podman/v5 5.5.2"],"slug":"CVE-2025-6032","body":"## Overview\n\nA flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2025-6032)\n\nAffected packages:\n\n- `github.com/containers/podman/v4 >= 4.8.0, <= 4.9.5`\n- `github.com/containers/podman/v5 < 5.5.2`\n\nPatched in:\n\n- `github.com/containers/podman/v5 5.5.2`\n\nSource: https://osv.dev/vulnerability/GHSA-65gg-3w2w-hr4h","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":45.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}