cbcvebase.
CVE-2026-57231
published 2026-06-26

CVE-2026-57231: Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.26%
17.4th percentile
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.

Affected

15 ranges
VendorProductVersion rangeFixed in
ansible-automation-platform-26eda-controller-rhel9
ansible-automation-platform-27eda-controller-rhel9
container-native-virtualizationocp-virt-validation-checkup-rhel9
container-tools_rhel8conmon
container-tools_rhel8podman
devspacesudi-base-rhel10
kata-containerskata-containers
kubernetescri-o
podman-container-toolspodman
podman_projectpodman
podman_projectpodman
podman_projectpodman>= 1.8.1 < 5.8.45.8.4
quayquay-builder-rhel8
quayquay-builder-rhel9
rhoso-operatorsprometheus-podman-exporter-rhel9

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.