{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/pulp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-90959"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pulpcore","Pulp Container"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","pulp"],"_cs_type":"advisory","_cs_vendors":["Pulp"],"content_html":"\u003cp\u003eA path traversal vulnerability exists in the pulpcore content upload API (CVE-2026-90959). The vulnerability stems from an insufficient validation of the 'file_url' parameter used by users with file repository privileges. While the application attempts to restrict file system access by rejecting URLs starting with 'file://', it fails to account for Python URL parser behavior that recognizes 'file:' without double slashes. By supplying a specially crafted URL, an authenticated user can bypass this check and utilize relative path traversal sequences (e.g., ../../) to read any file accessible to the Pulp server process. In environments utilizing Pulp Container, this flaw allows attackers to exfiltrate the container registry token signing private key, enabling the forgery of bearer tokens and providing unauthorized access to private container repositories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated attacker to read arbitrary files on the host system running the Pulp server process. In the context of Pulp Container, this leads to the compromise of the token signing private key, resulting in total loss of confidentiality and integrity for all private container repositories managed by the instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all affected Pulpcore and Pulp Container instances to the version containing the fix for CVE-2026-90959. Monitor web server access logs for anomalous requests to the content upload API containing traversal sequences such as '..%2f' or '..%5c' within the 'file_url' parameter.\u003c/p\u003e\n","date_modified":"2026-09-24T16:47:40Z","date_published":"2026-09-24T16:47:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pulpcore-path-traversal/","summary":"An authenticated path traversal vulnerability in the pulpcore content upload API allows users to bypass file scheme validation and read arbitrary files on the server process by manipulating the file_url parameter.","title":"Path Traversal in Pulpcore Content Upload API (CVE-2026-90959)","url":"https://feed.craftedsignal.io/briefs/2026-09-pulpcore-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Pulp","version":"https://jsonfeed.org/version/1.1"}