SB2026081523 - Input validation error in Podman
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-19730)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper input validation in the podman quadlet install --replace file replacement logic when replacing a Quadlet file with a smaller one. A local user can replace a Quadlet file with a shorter file that leaves trailing content from the original to disclose sensitive information.
User interaction is required to run the replace operation. With Volume Quadlets, preserved trailing content can include additional mounts that unintentionally expose container content.
Remediation
Install update from vendor's website.