VYPR
Unrated severityNVD Advisory· Published Jun 27, 2026

Debian podman: Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a…

CVE-2026-57231

Description

Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

Affected products

2
  • Podman/Podmaninferred2 versions
    <=5.8.4,>=1.8.1+ 1 more
    • (no CPE)range: <=5.8.4,>=1.8.1
    • (no CPE)range: >=1.8.1 <5.8.4

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.

CVE-2026-57231 · VYPR