CVE-2026-47906
published 2026-06-09CVE-2026-47906: Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary…
PriorityP346high8.6CVSS 3.1
AVLACLPRNUIRSCCHIHAH
EPSS
0.18%
7.4th percentile
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | dreamweaver | < 21.8 | 21.8 |
| adobe | dreamweaver_desktop | <= 21.7 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current
ghsa_unreviewed·2026-06-09
CVE-2026-47906 [HIGH] Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current
Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
VulDB
Adobe Dreamweaver Desktop up to 21.7 vulnerable third-party component (apsb26-62)
vuldb·2026-06-09·CVSS 8.6
CVE-2026-47906 [HIGH] Adobe Dreamweaver Desktop up to 21.7 vulnerable third-party component (apsb26-62)
A vulnerability was found in Adobe Dreamweaver Desktop up to 21.7. It has been declared as critical. The impacted element is an unknown function. Executing a manipulation can lead to dependency on vulnerable third-party component.
This vulnerability is registered as CVE-2026-47906. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-47906 yubihsm-connector: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 yubihsm-connector: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 yubihsm-connector: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-47906 direnv: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 direnv: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 direnv: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47906 aerc: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 aerc: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 aerc: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repo
Bugzilla
CVE-2025-47906 golang-github-atotto-clipboard: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-atotto-clipboard: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-atotto-clipboard: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's po
Bugzilla
CVE-2025-47906 golang-github-gogo-protobuf: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-gogo-protobuf: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-gogo-protobuf: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-47906 golang-github-git-5: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-git-5: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-git-5: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to clo
Bugzilla
CVE-2025-47906 golang-sigs-k8s-aws-iam-authenticator: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-sigs-k8s-aws-iam-authenticator: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-sigs-k8s-aws-iam-authenticator: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedo
Bugzilla
CVE-2025-47906 golang-github-gdamore-tcell: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-gdamore-tcell: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-gdamore-tcell: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-47906 cri-o1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 cri-o1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 cri-o1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 apache-cloudstack-cloudmonkey: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 apache-cloudstack-cloudmonkey: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 apache-cloudstack-cloudmonkey: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
Bugzilla
CVE-2025-47906 smtprelay: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 smtprelay: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 smtprelay: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 golang-github-hashicorp-sockaddr: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-hashicorp-sockaddr: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-hashicorp-sockaddr: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's
Bugzilla
CVE-2025-47906 meshbird: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 meshbird: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 meshbird: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 golang-sr-nelsam-hel: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-sr-nelsam-hel: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-sr-nelsam-hel: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-47906 golang-github-chromedp: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-chromedp: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-chromedp: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-47906 reposurgeon: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 reposurgeon: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 reposurgeon: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-47906 nwg-bar: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 nwg-bar: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 nwg-bar: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug r
Bugzilla
CVE-2025-47906 golang-entgo-ent: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-entgo-ent: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-entgo-ent: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close
Bugzilla
CVE-2025-47906 golang-github-projectdiscovery-chaos-client: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-projectdiscovery-chaos-client: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-projectdiscovery-chaos-client: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It i
Bugzilla
CVE-2025-47906 golang-github-containerd-cgroups-3: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-containerd-cgroups-3: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-containerd-cgroups-3: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora'
Bugzilla
CVE-2025-47906 host-spawn: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 host-spawn: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 host-spawn: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-47906 vultr: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 vultr: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 vultr: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug rep
Bugzilla
CVE-2025-47906 golang-github-googleapis-gnostic: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-googleapis-gnostic: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-googleapis-gnostic: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's
Bugzilla
CVE-2025-47906 golang-github-cucumber-godog: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-cucumber-godog: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-cucumber-godog: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's poli
Bugzilla
CVE-2025-47906 deepin-daemon: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 deepin-daemon: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 deepin-daemon: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-47906 cri-o: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 cri-o: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 cri-o: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug rep
Bugzilla
CVE-2025-47906 gmailctl: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 gmailctl: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 gmailctl: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 golang-k8s-sample-controller: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-k8s-sample-controller: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-k8s-sample-controller: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's poli
Bugzilla
CVE-2025-47906 deepin-api: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 deepin-api: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 deepin-api: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-47906 golang-github-gogo-googleapis: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-gogo-googleapis: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-gogo-googleapis: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
Bugzilla
CVE-2025-47906 git-credential-azure: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 git-credential-azure: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 git-credential-azure: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to cl
Bugzilla
CVE-2025-47906 OliveTin: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 OliveTin: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 OliveTin: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 asnmap: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 asnmap: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 asnmap: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47906 golang-github-hashicorp-serf: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-hashicorp-serf: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-hashicorp-serf: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's poli
Bugzilla
CVE-2025-47906 golang-github-rogpeppe-internal: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-rogpeppe-internal: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-rogpeppe-internal: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's p
Bugzilla
CVE-2025-47906 golang-k8s-sample-apiserver: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-k8s-sample-apiserver: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-k8s-sample-apiserver: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-47906 kubernetes1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 kubernetes1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 kubernetes1.29: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
Bugzilla
CVE-2025-47906 nebula: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 nebula: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 nebula: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47906 golang-github-theupdateframework-notary: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-theupdateframework-notary: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-theupdateframework-notary: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fe
Bugzilla
CVE-2025-47906 golang-gvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-gvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-gvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-47906 ollama: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 ollama: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 ollama: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47906 anubis: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 anubis: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 anubis: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug re
Bugzilla
CVE-2025-47906 grafana-pcp: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 grafana-pcp: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 grafana-pcp: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all b
Bugzilla
CVE-2025-47906 cadvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 cadvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 cadvisor: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug
Bugzilla
CVE-2025-47906 golang-x-perf: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-x-perf: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-x-perf: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-47906 clash-meta: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 clash-meta: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 clash-meta: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-47906 golang-github-moby-buildkit: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-moby-buildkit: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-moby-buildkit: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's polic
Bugzilla
CVE-2025-47906 golang-github-mailru-easyjson: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-github-mailru-easyjson: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-github-mailru-easyjson: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's pol
Bugzilla
CVE-2025-47906 golang-k8s-kube-openapi: Unexpected paths returned from LookPath in os/exec [fedora-42]
bugzilla·2025-09-26·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 golang-k8s-kube-openapi: Unexpected paths returned from LookPath in os/exec [fedora-42]
CVE-2025-47906 golang-k8s-kube-openapi: Unexpected paths returned from LookPath in os/exec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-47906 gum: Unexpected paths returned from LookPath in os/exec [epel-10]
bugzilla·2025-09-25·CVSS 6.5
CVE-2025-47906 [MEDIUM] CVE-2025-47906 gum: Unexpected paths returned from LookPath in os/exec [epel-10]
CVE-2025-47906 gum: Unexpected paths returned from LookPath in os/exec [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
---
FEDORA-EPEL-2026-5f723f26cd (gum-0.17.0-3.el10_3) has been submitted as an update to Fedora EPEL 10.
2026-06-09
Published