CVE-2025-6032High· 8.3▾ TwilightA flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.5%
A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/containers/podman/v4 >= 4.8.0, <= 4.9.5github.com/containers/podman/v5 < 5.5.2Patched in:
github.com/containers/podman/v5 5.5.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-1753High· 8.6Podman affected by CVE-2024-1753 container escape at build time
CVE-2022-27649High· 7.5Podman's default inheritable capabilities for linux container not empty
CVE-2022-1227High· 8.8Podman publishes a malicious image to public registries
CVE-2026-24281High· 7.4Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certifica…
CVE-2022-27651Medium· 6.8Non-empty default inheritable capabilities for linux container in Buildah
CVE-2021-3602Medium· 5.5Buildah processes using chroot isolation may leak environment values to intermediate processes