Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34045

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 8.2
CVSS3: 9.1
EPSS Низкий

Описание

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linuxfoundation:podman_desktop:*:*:*:*:*:*:*:*
Версия до 1.26.2 (исключая)

EPSS

Процентиль: 38%
0.00474
Низкий

8.2 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-209
CWE-209
CWE-770

Связанные уязвимости

CVSS3: 8.2
redhat
4 месяца назад

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.

CVSS3: 9.1
fstec
4 месяца назад

Уязвимость компонента WebView HTTP Server программного средства управления и запуска OCI-контейнеров Podman, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.00474
Низкий

8.2 High

CVSS3

9.1 Critical

CVSS3

Дефекты

CWE-209
CWE-209
CWE-770