CVE-2026-103870Medium· 5.0▾ SunlitA flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the ta…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103884Medium· 6.5A flaw was found in the X.509 client certificate authenticator of Keycloak
CVE-2026-103754Medium· 5.9A flaw was found in ansible-runner
CVE-2026-101295High· 7.3Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction
CVE-2023-27534Low· 3.7curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)
CVE-2026-107121Medium· 6.5A flaw was found in the SMTP email configuration handling of the keycloak-services component
CVE-2026-103869Medium· 6.5A flaw was found in pulp-ansible's bearer-token refresh for collection remotes