Database/Container, Kubernetes & orchestration
Podman: Image env var with a key and no value causes Podman to pass the host's value of that variable
CVSS 7.5CVE-2026-57231Container, Kubernetes & orchestrationcurated
Impact
Image env var with a key and no value causes Podman to pass the host's value of that variable into the container; host secret leakage
Who can reach it
Malicious image
What to do
Upgrade Podman to 5.8.4+; sanitise the environment of any host that runs untrusted images
References
Related entries
- Podman: Incorrect supplementary group handlingCVE-2022-2989 · PodmanHigh
- Podman: File permissions not checked for non-root users in a privileged containerCVE-2021-20188 · PodmanHigh
- Podman: TOCTOU during volume export lets a symlink swap expose arbitrary host filesCVE-2023-0778 · PodmanMedium
- Podman: Rootless containers see all traffic as coming from 127.0.0.1, defeating localhost-trust checksCVE-2021-20199 · PodmanMedium
- Podman: Malicious image WORKDIR symlink creates directories or changes ownership on the host filesystemCVE-2026-55686 · PodmanMedium
- Podman: Malicious image causes privilege escalation when a user runs `podman top`CVE-2022-1227 · PodmanHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.