---
id: CVE-2025-6032
title: A flaw was found in Podman
summary: >-
  A flaw was found in Podman. The podman machine init command fails to verify
  the TLS certificate when downloading the VM images from an OCI registry. This
  issue results in a Man In The Middle attack.
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-295
published: '2025-06-24'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6032'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:10295'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10549'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10550'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10551'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:10668'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11359'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11363'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11677'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:11681'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:15397'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9726'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9751'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:9766'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-6032'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2372501'
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3
    label: secalert@redhat.com
  - url: >-
      https://github.com/containers/podman/security/advisories/GHSA-65gg-3w2w-hr4h
    label: secalert@redhat.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6032'
  - url: 'https://github.com/containers/podman'
tags:
  - nvd
  - osv
  - go
epss: 0.00479
epssPercentile: 0.40537
ingestedAt: '2026-06-29T13:24:34.383Z'
aliases:
  - GHSA-65gg-3w2w-hr4h
  - GO-2025-3777
ecosystem: go
vendor: containers
product: github.com/containers/podman/v4
affected:
  - 'github.com/containers/podman/v4 >= 4.8.0, <= 4.9.5'
  - github.com/containers/podman/v5 < 5.5.2
patched:
  - github.com/containers/podman/v5 5.5.2
---

## Overview

A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2025-6032)

Affected packages:

- `github.com/containers/podman/v4 >= 4.8.0, <= 4.9.5`
- `github.com/containers/podman/v5 < 5.5.2`

Patched in:

- `github.com/containers/podman/v5 5.5.2`

Source: https://osv.dev/vulnerability/GHSA-65gg-3w2w-hr4h
