Bug 2456283 (CVE-2026-34045) - CVE-2026-34045 podman-desktop: Podman Desktop: Denial of Service and Information Disclosure via unauthenticated HTTP server
Summary: CVE-2026-34045 podman-desktop: Podman Desktop: Denial of Service and Informat...
Keywords:
Status: NEW
Alias: CVE-2026-34045
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-07 22:01 UTC by OSIDB Bzimport
Modified: 2026-05-05 19:14 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:13867 0 None None None 2026-05-05 19:14:09 UTC

Description OSIDB Bzimport 2026-04-07 22:01:57 UTC
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.

Comment 1 odockal 2026-04-10 08:51:40 UTC
At this point, we already have a RPM build ready also with RHSA errata: https://errata.devel.redhat.com/advisory/details/165101, where we have a fix for this CVE. We need to dispatch this bug into appropriate state so we can ship the RPM. The cve was also patched upstream: https://github.com/podman-desktop/podman-desktop/security/advisories/GHSA-2q88-39rh-gxvv.

Comment 3 errata-xmlrpc 2026-05-05 19:14:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:13867 https://access.redhat.com/errata/RHSA-2026:13867


Note You need to log in before you can comment on or make changes to this bug.