Known vulnerabilities in flatpak (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:flatpak_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 12
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting flatpak (Red Hat package) flatpak (Red Hat package) is affected by 12 known vulnerabilities: 1 high, 4 medium, 7 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125296 - Improper Access Control
CVE-2026-34078
CWE-284 High
No
No
1.12.7-5.el9_2.1, 1.12.9-1.el8_6, 1.12.9-1.el8_8, 1.12.9-2.el8_4, 1.12.9-3.el7_9, 1.12.9-3.el9_4.1, 1.12.9-4.el8_10, 1.12.9-4.el9_6.1, 1.12.9-4.el9_8.1, 1.16.0-5.el10_0.2, 1.16.0-9.el10_2.1 08.04.2026 SB2026040858
SB2026040865
SB2026040866
and 28 more
#VU125295 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-34079
CWE-22 Low
No
No
1.12.7-5.el9_2.1, 1.12.9-1.el8_6, 1.12.9-1.el8_8, 1.12.9-2.el8_4, 1.12.9-3.el7_9, 1.12.9-3.el9_4.1, 1.12.9-4.el8_10, 1.12.9-4.el9_6.1, 1.12.9-4.el9_8.1, 1.16.0-5.el10_0.2, 1.16.0-9.el10_2.1 08.04.2026 SB2026040858
SB2026040865
SB2026040866
and 28 more
#VU96049 - UNIX Symbolic Link (Symlink) Following
CVE-2024-42472
CWE-61 Low
No
No
1.0.9-15.el7_9, 1.6.2-9.el8_2, 1.8.5-7.el8_4, 1.8.7-4.el8_6, 1.10.7-4.el8_8, 1.12.5-5.el9_0, 1.12.7-5.el9_2, 1.12.9-3.el8_10, 1.12.9-3.el9_4, 1.12.9-3.el9_5 15.08.2024 SB2024081541
SB2024081542
SB2024081553
and 29 more
#VU88827 - Argument Injection or Modification
CVE-2024-32462
CWE-88 Low
No
No
1.0.9-13.el7_9, 1.6.2-7.el8_2, 1.8.5-5.el8_4, 1.8.7-2.el8_6, 1.10.7-2.el8_8, 1.12.5-3.el9_0, 1.12.7-3.el9_2, 1.12.9-1.el8_10, 1.12.9-1.el9_4 19.04.2024 SB2024041902
SB2024041903
SB2024042944
and 29 more
#VU73856 - Improper input validation
CVE-2017-5226
CWE-20 Medium
No
No
1.0.2-5.el7_6, 1.0.6-3.el8_0 20.03.2023 SB2017032918
SB2019032618
SB2021101519
and 8 more
#VU73835 - Improper input validation
CVE-2023-28100
CWE-20 Low
No
No
1.10.8-1.el8, 1.12.8-1.el9 20.03.2023 SB2023032035
SB2023033142
SB2023033143
and 15 more
#VU73834 - Improper input validation
CVE-2023-28101
CWE-20 Medium
No
No
1.10.8-1.el8, 1.12.8-1.el9 20.03.2023 SB2023032035
SB2023033142
SB2023033143
and 15 more
#VU59654 - Permissions, Privileges, and Access Controls
CVE-2021-43860
CWE-264 Medium
No
No
1.8.7-1.el8 17.01.2022 SB2022011715
SB2022012525
SB2022051141
and 8 more
#VU57176 - Permissions, Privileges, and Access Controls
CVE-2021-41133
CWE-264 Low
No
No
1.0.9-5.el8_1, 1.0.9-12.el7_9, 1.6.2-6.el8_2, 1.8.5-4.el8_4 08.10.2021 SB2021100815
SB2021101417
SB2021110212
and 17 more
#VU51443 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2021-21381
CWE-74 Medium
No
No
1.0.9-4.el8_1, 1.0.9-11.el7_9, 1.6.2-5.el8_2, 1.6.2-6.el8_3 14.03.2021 SB2021031112
SB2021031403
SB2021031408
and 11 more
#VU49587 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-21261
CWE-94 Low
No
No
1.0.9-3.el8_1, 1.0.9-10.el7_9, 1.6.2-4.el8_2, 1.6.2-5.el8_3 14.01.2021 SB2021011821
SB2021011822
SB2021012105
and 12 more
#VU32022 - Security Features
CVE-2019-10063
CWE-254 Low
No
No
1.0.2-5.el7_6, 1.0.6-3.el8_0 26.03.2019 SB2019032618
SB2019050426
SB2019050662
and 3 more