Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-107935: Red Hat products allow remote file deletion via gvproxy
CVE-2026-107935 · published 1 day ago
Summary
The gvproxy component used in several Red Hat products can delete any file on the host if an attacker tricks it with a special request. This happens because the system does not check the file path supplied to the expose endpoint. Apply the vendor's update or disable the vulnerable endpoint until a patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | red hat | red hat build of podman desktop | All versions |
| – | red hat | red hat certification program for red hat enterprise linux 9 | All versions |
| – | red hat | red hat edge manager 1 | All versions |
| – | red hat | red hat enterprise linux 10 | All versions |
| – | red hat | red hat enterprise linux 8 | All versions |
| – | red hat | red hat enterprise linux 9 | All versions |
| – | red hat | red hat hardened images | All versions |
| – | red hat | red hat openshift container platform 4 | All versions |
| – | red hat | red hat openshift dev spaces | All versions |
| – | red hat | red hat openstack platform 18.0 | All versions |
| Debian:13 | debian | golang-github-containers-gvisor-tap-vsocks | All versions |
Original advisory text
DEBIAN-CVE-2026-107935
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
References
- https://access.redhat.com/security/cve/CVE-2026-107935 vdb-entry x_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2548382 issue-tracking x_refsource_REDHAT
- https://github.com/containers/gvisor-tap-vsock/pull/718
- https://redhat.atlassian.net/browse/RHDESK-550
- https://security-tracker.debian.org/tracker/CVE-2026-107935 Vendor Advisory
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit (estimated)
- Gives an attacker partial control (estimated)
Type
CWE-22Path Traversal
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen9 Oct 2026
Track software like this
Free during beta