REDHAT-BUG-2542628: Low severity Flatpak Flatpak vulnerability

Published Sep 28, 2026
·
Updated

GHSA-7rvf-rqr3-43j4 (https://github.com/flatpak/flatpak/security/advisories/GHSA-7rvf-rqr3-43j4)

Description: When downloading apps or runtimes from an OCI repository that requires authentication, the OCI authentication token is written with the default permissions 0644. On multi-user systems this allows other local users to read the token file. This is related to GHSA-r9w3-qx54-qvc8 but with a different impact: unlike that issue, this one is not mitigated by a restrictive umask. libostree repositories such as Flathub are not affected; this only applies to apps, runtimes, or extensions downloaded from an OCI repository (such as those used by Fedora).

Mitigation: No known mitigation other than updating, or using libostree repositories (e.g. Flathub) or unauthenticated/public OCI repositories instead. Patched in 1.18.4 by commit f911bbf0 ("oci: Stop persisting bearer token to child repo on disk"). Credit: Found by AISLE in cooperation with Red Hat.

Affected Software

1 affected component
Flatpak Flatpak<1.18.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade flatpak to a version that resolves this vulnerability.

    Fixed in 1.18.4Patch f911bbf0
  2. Compensating control

    Use libostree repositories such as Flathub, or unauthenticated/public OCI repositories, instead of authenticated OCI repositories.

Event History

Sep 28, 2026
Data Sourced
via Red Hat·07:55 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed to token disclosure?

The issue affects systems that download apps, runtimes, or extensions from OCI repositories requiring authentication, particularly multi-user systems where another local user can read the token file. Downloads from libostree repositories such as Flathub are not affected.

2

Does a restrictive umask prevent this issue?

No. Unlike the related issue GHSA-r9w3-qx54-qvc8, this behavior is not mitigated by using a restrictive umask.

3

What can be done if an update cannot be installed immediately?

There is no known direct mitigation other than updating. As alternatives, use libostree repositories such as Flathub or unauthenticated/public OCI repositories instead of authenticated OCI repositories.

4

What version contains the fix?

The issue was patched in Flatpak 1.18.4, with a change that stops persisting the bearer token to the child repository on disk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203