<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Gvproxy (Gvisor-Tap-Vsock) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gvproxy-gvisor-tap-vsock/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 13:22:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gvproxy-gvisor-tap-vsock/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Deletion via Path Traversal in gvproxy</title><link>https://feed.craftedsignal.io/briefs/2026-10-gvproxy-path-traversal/</link><pubDate>Fri, 09 Oct 2026 13:22:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gvproxy-path-traversal/</guid><description>An unauthenticated path traversal vulnerability in the gvproxy component of gvisor-tap-vsock allows attackers to delete arbitrary files on the host filesystem via the /services/forwarder/expose endpoint.</description><content:encoded><![CDATA[<p>CVE-2026-107935 is a critical path traversal vulnerability residing in gvproxy, which serves as a network forwarder within the gvisor-tap-vsock package. The flaw exists due to insufficient input validation on the /services/forwarder/expose API endpoint. By submitting a crafted request containing a malicious socket path, an unauthenticated attacker can manipulate the application to perform file operations outside of the intended directory. Because the application interacts directly with the host system, this lack of path sanitization allows an attacker to trigger the deletion of arbitrary files on the host filesystem. This vulnerability poses a significant risk to the integrity of systems utilizing gvproxy, particularly in containerized or virtualized environments where host-level access is highly sensitive. Defenders should prioritize auditing web-based logs for suspicious POST requests to the affected endpoint and identify deployments of gvisor-tap-vsock to prepare for patching.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in arbitrary file deletion on the host operating system. This can lead to system instability, service disruption, or the removal of sensitive configuration files and security-critical binaries. Any environment utilizing the gvisor-tap-vsock stack for network forwarding is potentially at risk of host-level impact if the gvproxy service is exposed to an untrusted network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor webserver and proxy logs for incoming requests targeting the /services/forwarder/expose URI to identify potential exploitation attempts.</li>
<li>Audit environments to locate instances of gvisor-tap-vsock and gvproxy.</li>
<li>Apply patches immediately upon release by the maintainers of the gvisor-tap-vsock package.</li>
<li>Ensure that the gvproxy endpoint is restricted to authorized internal traffic only, preventing unauthenticated access from untrusted sources.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>path-traversal</category><category>rce-prevention</category></item></channel></rss>