top of page
perceptive_background_267k.jpg

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows…

Published:

6 april 2026 om 22:00:00

Alert date:

7 april 2026 om 22:01:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Security Tools

Podman Desktop versions prior to 1.26.2 contain a critical vulnerability in an unauthenticated HTTP server that allows remote network attackers to trigger denial-of-service conditions and extract sensitive information. The vulnerability exploits missing connection limits and timeouts to exhaust file descriptors and kernel memory, potentially causing application crashes or full host freeze. Additionally, verbose error responses disclose internal paths and system details including usernames on Windows systems. The vulnerability requires no authentication or user interaction and is remotely exploitable over the network. This issue has been fixed in version 1.26.2.

Technical details

Mitigation steps:

Affected products:

Podman Desktop

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page