cbcvebase.
CVE-2026-56860
published 2026-08-13

CVE-2026-56860: Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in…

PriorityP434medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.52%
42.2th percentile
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

Affected

108 ranges· showing 25
VendorProductVersion rangeFixed in
3scale-amp23scale-operator-bundle
advanced-cluster-securityrhacs-main-rhel8
advanced-cluster-securityrhacs-main-rhel9
alboaws-load-balancer-operator
alboaws-load-balancer-rhel8-operator
ansible-automation-platform-26receptor-rhel9
ansible-automation-platform-27receptor-rhel9
ansible-automation-platformplatform-operator-bundle
apachethrift
build-of-trusteetrustee-rhel9-operator
buildah_projectbuildah
cert-managerjetstack-cert-manager-rhel9
complianceopenshift-compliance-operator-bundle
complianceopenshift-selinuxd-rhel8
confidential-containerstrustee
container-native-virtualizationkubemacpool-rhel9
container-tools_rhel8buildah
container-tools_rhel8conmon
container-tools_rhel8containernetworking-plugins
container-tools_rhel8crun
container-tools_rhel8oci-seccomp-bpf-hook
container-tools_rhel8podman
container-tools_rhel8runc
container-tools_rhel8skopeo
container-tools_rhel8toolbox

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.