VYPR

Pulp

by Red Hat

CVEs (1)

  • CVE-2026-90959HigSep 24, 2026
    risk 0.53cvss 8.1epss —

    A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison…