Bug 2524130 (CVE-2026-72924)
| Summary: | CVE-2026-72924 github.com/cli/cli: GitHub CLI: Forwarded services exposed on all network interfaces by default | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anjoseph, eglynn, jjoyce, jprabhak, jpretori, jschluet, lhh, mburns, mgarciac, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in GitHub CLI. The `gh codespace ports forward` command, by default, exposes forwarded services on all local network interfaces. This allows a network-adjacent attacker to access these services through the user's machine while port forwarding is active, even if the original Codespaces port is private. This can lead to unauthorized access to internal services.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-25 21:23:15 UTC
|