CVE-2025-4953
published 2025-09-16CVE-2025-4953: A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can…
PriorityP347high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.60%
45.0th percentile
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libpod | < podman 5.3.2+ds1-1 (forky) | podman 5.3.2+ds1-1 (forky) |
| debian | podman | < podman 5.3.2+ds1-1 (forky) | podman 5.3.2+ds1-1 (forky) |
| github.com | containers_podman_v5 | 0 – 5.5.0 | — |
| msrc | azl3_conmon_2.1.8-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_runc_1.3.3-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_skopeo_1.14.4-6_on_azure_linux_3.0 | — | — |
| podman_project | podman | >= 0 < 5.3.2+ds1-1 | 5.3.2+ds1-1 |
| podman_project | podman | >= 0 < 5.3.2+ds1-1 | 5.3.2+ds1-1 |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
osv·2025-09-17
CVE-2025-4953 Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
Podman Creates Temporary File with Insecure Permissions in github.com/containers/podman
OSV
CVE-2025-4953: A flaw was found in Podman
osv·2025-09-16·CVSS 7.4
CVE-2025-4953 [HIGH] CVE-2025-4953: A flaw was found in Podman
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
GHSA
Podman Creates Temporary File with Insecure Permissions
ghsa·2025-09-16
CVE-2025-4953 [HIGH] CWE-378 Podman Creates Temporary File with Insecure Permissions
Podman Creates Temporary File with Insecure Permissions
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
OSV
Podman Creates Temporary File with Insecure Permissions
osv·2025-09-16
CVE-2025-4953 [HIGH] Podman Creates Temporary File with Insecure Permissions
Podman Creates Temporary File with Insecure Permissions
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
Red Hat
podman: Build Context Bind Mount
vendor_redhat·2025-09-16·CVSS 7.4
CVE-2025-4953 [HIGH] CWE-378 podman: Build Context Bind Mount
podman: Build Context Bind Mount
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
Statement: This issue is classified as Moderate rather than Important because exploitation requires several preconditions: an attacker must have unprivile
Microsoft
Podman: build context bind mount
vendor_msrc·2025-09-09·CVSS 7.4
CVE-2025-4953 [HIGH] CWE-378 Podman: build context bind mount
Podman: build context bind mount
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Debian
CVE-2025-4953: libpod - A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --...
vendor_debian·2025·CVSS 7.4
CVE-2025-4953 [HIGH] CVE-2025-4953: libpod - A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --...
A flaw was found in Podman. In a Containerfile or Podman, data written to RUN --mount=type=bind mounts during the podman build is not discarded. This issue can lead to files created within the container appearing in the temporary build context directory on the host, leaving the created files accessible.
Scope: local
bookworm: open
bullseye: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-26081 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26081 [HIGH] CVE-2026-26081 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26081 :
HAProxy vulnerability analysis and mitigation
crash via INITIAL packet for the NEW_TOKEN format
Source : NVD
Published February 12, 2026
CNA Score N/A
Affected Technologies
HAProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
haproxy
Sources
NVD
Debian 13, 14 Has Fix Added at: Feb 12, 2026
Ubuntu 25.10 Severity MEDIUM Has Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related HAProxy vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV
Wiz
CVE-2026-26080 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26080 [HIGH] CVE-2026-26080 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26080 :
HAProxy vulnerability analysis and mitigation
crash in parsing frame type
Source : NVD
Published February 12, 2026
CNA Score N/A
Affected Technologies
HAProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) N/A
Exploitation Probability (EPSS) N/A
Affected packages and libraries
haproxy
Sources
NVD
Debian 14 Has Fix Added at: Feb 12, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related HAProxy vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-11230
HIGH
7.5
HAProxy
haproxy-2.4
No
Bugzilla
CVE-2025-4953 podman: Build Context Bind Mount [fedora-all]
bugzilla·2025-09-16·CVSS 7.4
CVE-2025-4953 [HIGH] CVE-2025-4953 podman: Build Context Bind Mount [fedora-all]
CVE-2025-4953 podman: Build Context Bind Mount [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that a
https://access.redhat.com/errata/RHSA-2024:8690https://access.redhat.com/errata/RHSA-2025:15904https://access.redhat.com/errata/RHSA-2025:16724https://access.redhat.com/errata/RHSA-2025:16729https://access.redhat.com/errata/RHSA-2025:17669https://access.redhat.com/errata/RHSA-2025:22265https://access.redhat.com/errata/RHSA-2025:22275https://access.redhat.com/errata/RHSA-2025:22695https://access.redhat.com/errata/RHSA-2025:22724https://access.redhat.com/errata/RHSA-2025:22732https://access.redhat.com/errata/RHSA-2025:23113https://access.redhat.com/errata/RHSA-2025:2703https://access.redhat.com/errata/RHSA-2026:0316https://access.redhat.com/security/cve/CVE-2025-4953https://bugzilla.redhat.com/show_bug.cgi?id=2367235https://github.com/containers/podman/pull/25173
2025-09-16
Published