PT-2026-31021 · Red Hat · Podman-Desktop

C-H4Ck-0

·

Published

2026-04-07

·

Updated

2026-05-21

·

CVE-2026-34045

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Podman Desktop versions prior to 1.26.2
Description Podman Desktop, a graphical tool for container and Kubernetes development, contains a flaw where an unauthenticated HTTP server can be exploited by network attackers. This allows for denial-of-service conditions through exhaustion of file descriptors and kernel memory, potentially leading to application crashes or a complete host freeze. Verbose error responses reveal internal paths and system details, including usernames on Windows systems, which could aid in further exploitation. The issue is exploitable over the network without authentication or user interaction.
Recommendations Update to version 1.26.2 or later.

Exploit

Fix

DoS

Improper Access Control

Generation of Error Message Containing Sensitive Information

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-34045
RHSA-2026:13867

Affected Products

Podman-Desktop