CVE-2026-57231
published 2026-06-26CVE-2026-57231: Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.26%
17.4th percentile
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-27 | eda-controller-rhel9 | — | — |
| container-native-virtualization | ocp-virt-validation-checkup-rhel9 | — | — |
| container-tools_rhel8 | conmon | — | — |
| container-tools_rhel8 | podman | — | — |
| devspaces | udi-base-rhel10 | — | — |
| kata-containers | kata-containers | — | — |
| kubernetes | cri-o | — | — |
| podman-container-tools | podman | — | — |
| podman_project | podman | — | — |
| podman_project | podman | — | — |
| podman_project | podman | >= 1.8.1 < 5.8.4 | 5.8.4 |
| quay | quay-builder-rhel8 | — | — |
| quay | quay-builder-rhel9 | — | — |
| rhoso-operators | prometheus-podman-exporter-rhel9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
podman: Podman: Information disclosure via malicious container image environment variables
vendor_redhat·2026-06-26·CVSS 7.5
CVE-2026-57231 [HIGH] CWE-914 podman: Podman: Information disclosure via malicious container image environment variables
podman: Podman: Information disclosure via malicious container image environment variables
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
A flaw was found in Podman, a tool for managing OCI containers and pods. A malicious container image can be crafted with an environment variable tha
VulDB
podman-container-tools podman up to 5.8.3 information disclosure (EUVD-2026-39807 / Nessus ID 323664)
vuldb·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] podman-container-tools podman up to 5.8.3 information disclosure (EUVD-2026-39807 / Nessus ID 323664)
A vulnerability, which was classified as problematic, was found in podman-container-tools podman up to 5.8.3. This affects an unknown part. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-57231. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-57231 cri-o1.30: Podman: Information disclosure via malicious container image environment variables [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 cri-o1.30: Podman: Information disclosure via malicious container image environment variables [fedora-all]
CVE-2026-57231 cri-o1.30: Podman: Information disclosure via malicious container image environment variables [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that ar
Bugzilla
CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [fedora-all]
CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that a
Bugzilla
CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [epel-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [epel-all]
CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment va
Bugzilla
CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [epel-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [epel-all]
CVE-2026-57231 podman-tui: Podman: Information disclosure via malicious container image environment variables [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are
Bugzilla
CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables [fedora-all]
CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are s
Bugzilla
CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [fedora-all]
CVE-2026-57231 prometheus-podman-exporter: Podman: Information disclosure via malicious container image environment variables [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment
Bugzilla
CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables
bugzilla·2026-06-26·CVSS 7.5
CVE-2026-57231 [HIGH] CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables
CVE-2026-57231 podman: Podman: Information disclosure via malicious container image environment variables
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
2026-06-26
Published