PT-2026-31021 · Red Hat · Podman-Desktop
C-H4Ck-0
·
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-34045
CVSS v3.1
8.2
High
| AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Podman Desktop versions prior to 1.26.2
Description
Podman Desktop, a graphical tool for container and Kubernetes development, contains a flaw where an unauthenticated HTTP server can be exploited by network attackers. This allows for denial-of-service conditions through exhaustion of file descriptors and kernel memory, potentially leading to application crashes or a complete host freeze. Verbose error responses reveal internal paths and system details, including usernames on Windows systems, which could aid in further exploitation. The issue is exploitable over the network without authentication or user interaction.
Recommendations
Update to version 1.26.2 or later.
Fix
DoS
Generation of Error Message Containing Sensitive Information
Improper Access Control
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Podman-Desktop