VYPR

pulp-rpm

by Red Hat

CVEs (1)

  • CVE-2026-103870MedOct 7, 2026
    risk 0.33cvss 5.0epss —

    A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's…