RHSA-2026:57590: Important: rh-podman-desktop security, bug fix, and enhancement update
Important: rh-podman-desktop security, bug fix, and enhancement update
Other sources
Red Hat build of Podman Desktop is a graphical tool for managing containers using Podman. It allows users to run, manage, and configure containers and container images using a desktop GUI.Security Fix(es): github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986) ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) protobufjs: protobufjs: Denial of Service via crafted JSON descriptors (CVE-2026-45740) ws: ws: Uninitialized memory disclosure via websocket.close() with TypedArray (CVE-2026-45736) devalue: devalue: Excessive memory consumption via deserialization of sparse arrays (CVE-2026-42570) tmp: path Traversal via unsanitized prefix/postfix enables directory escape (CVE-2026-44705) form-data: form-data: Form field override via CRLF injection (CVE-2026-12143) webpack-dev-server: webpack-dev-server: Information disclosure and denial of service via improper proxy configuration (CVE-2026-9595) ws: ws: Denial of Service via memory exhaustion from small WebSocket fragments (CVE-2026-48779) extract-zip: github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass (CVE-2026-56876) fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization (CVE-2026-13676) brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874) tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873) js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) protobufjs: protobufjs: Denial of Service via crafted .proto schema (CVE-2026-59877) grpc-js: @grpc/grpc-js: Server crash via malformed HTTP/2 stream initiation (CVE-2026-48068) linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801) dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978) brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623) postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153) brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) Bug Fix(es) and Enhancement(s): Release RH Podman Desktop 1.1.2 to RHEL 10.2 Extensions (JIRA:RHEL-238929) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-podman-desktopto a version that resolves this vulnerability.Fixed in 1.1.2-1.el10_2 - Upgrade
Upgrade
rh-podman-desktopto a version that resolves this vulnerability.Fixed in 1.1.2Patch RHEL-238929 - Upgrade
Upgrade
github.com/go-jose/go-joseto a version that resolves this vulnerability.Fixed in v4Patch CVE-2026-34986
Event History
Frequently Asked Questions
Which platform is covered by this advisory?
The advisory covers Red Hat Enterprise Linux for x86_64.
How urgent is this update?
It is rated High severity, with a risk value of 33.
When was this advisory issued?
It was published and last modified on 2026-08-20.