---
id: CVE-2026-103870
title: A flaw was found in pulp-rpm when it publishes a distribution tree
summary: >-
  A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and
  variant ids from .treeinfo are used as directory names. A user who can sync or
  upload that tree can make the publish task create a new directory outside the
  ta…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'
cwe:
  - CWE-22
vendor: Red Hat
product: python3.12-pulp-rpm
affected:
  - python3.12-pulp-rpm (all versions)
  - python-pulp-rpm (all versions)
  - python-pulp-rpm
  - python-pulp-rpm-client
  - python-pulp-rpm-client
  - rhui5/rhua-rhel9
  - rhui5/rhua-tp-rhel9
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T06:16:35.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103870'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-103870'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2544606'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T08:20:03.935Z'
---

## Overview

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
