Input validation error in Podman - CVE-2026-19730

 

Input validation error in Podman - CVE-2026-19730

Published: August 15, 2026


Vulnerability identifier: #VU142668
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19730
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper input validation in the podman quadlet install --replace file replacement logic when replacing a Quadlet file with a smaller one. A local user can replace a Quadlet file with a shorter file that leaves trailing content from the original to disclose sensitive information.

User interaction is required to run the replace operation. With Volume Quadlets, preserved trailing content can include additional mounts that unintentionally expose container content.


Affected software

Podman

How to mitigate CVE-2026-19730

Install security update from vendor's website.

Podman - addressed in versions 5.8.6, 6.0.0

External References

Related Security Bulletins