VulnSea

podman vulnerabilities

CVEs whose affected-version data names the podman package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-76781Medium· 5.5
5d ago

A flaw was found in libxml2

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a `nextCatalog` element lacks its mandatory `catalog` …

SunlitRed Hat · libxml2-mainEPSS 0.16%via NVD
CVE-2025-11395Medium· 5.5
1w ago

A flaw was found in Podman

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

SunlitRed Hat · buildahEPSS 0.19%via NVD
CVE-2026-79699Medium· 4.4
1w ago

A flaw was found in the containers/storage library

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by st…

SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.13%via NVD
CVE-2026-79705Medium· 4.5
1w ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.25%via NVD
CVE-2026-74860High· 8.5
2w ago

A flaw was found in libxml2 with Python bindings enabled

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This…

TwilightRed Hat · libxml2-mainEPSS 0.35%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

TwilightRed Hat · podmanEPSS 1.1%via NVD
podman vulnerabilities (CVEs) · VulnSea