{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apodman_projectpodman/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:*","cpe:2.3:a:podman_project:podman:6.0.0:rc1:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-57231"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Podman (\u003c 5.8.4, \u003c 6.0.0, \u003c= 4.9.5, \u003c= 3.4.7, \u003c= 2.2.1)"],"_cs_severities":["high"],"_cs_tags":["container-security","credential-theft"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003ePodman contains a high-severity vulnerability (CVE-2026-57231) that enables the unauthorized exfiltration of host environment variables into a running container. The issue arises from flawed parsing logic within the container image configuration; specifically, if an image defines environment variables without an accompanying value, or utilizes wildcard characters such as an asterisk, Podman improperly interprets these entries.\u003c/p\u003e\n\u003cp\u003eBy design, the Podman \u003ccode\u003e--env\u003c/code\u003e flag is intended to map host variables to a container. Due to the reuse of this parsing logic for image configuration, an attacker can craft a container image that forces the container engine to mirror sensitive host-side environment variables - such as API keys, database credentials, or tokens - directly into the container's process space upon execution. This vulnerability affects multiple versions of Podman across the v2 through v6 branches. Defenders should prioritize upgrading to patched versions or implementing strict image validation processes.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to gain unauthorized access to sensitive host environment variables. In cloud or CI/CD environments where containers are frequently executed, this could lead to the exposure of credentials, service account tokens, or environment configuration secrets, potentially facilitating lateral movement or privilege escalation within the host or broader infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Podman to a secure version as specified in the advisory: v5.8.4, v6.0.0, or higher depending on the deployment branch.\u003c/li\u003e\n\u003cli\u003ePrior to execution, audit untrusted container images using the command: \u003ccode\u003epodman image inspect --format '{{.Config.Env}}' \u0026lt;image\u0026gt;\u003c/code\u003e. Identify and block images containing environment variables that lack a key-value assignment (i.e., variables not following the \u003ccode\u003ekey=value\u003c/code\u003e format).\u003c/li\u003e\n\u003cli\u003eEnforce strict policies regarding the ingestion of images from public or untrusted container registries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T20:05:13Z","date_published":"2026-09-24T20:05:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-podman-env-leak/","summary":"A vulnerability in Podman allows malicious container images containing malformed environment variables to exfiltrate host environment variables into the container environment at runtime.","title":"Podman Environment Variable Leak via Malformed Container Images","url":"https://feed.craftedsignal.io/briefs/2026-09-podman-env-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}