Input validation error in Podman - CVE-2026-19730
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper input validation in the podman quadlet install --replace file replacement logic when replacing a Quadlet file with a smaller one. A local user can replace a Quadlet file with a shorter file that leaves trailing content from the original to disclose sensitive information.
User interaction is required to run the replace operation. With Volume Quadlets, preserved trailing content can include additional mounts that unintentionally expose container content.