Sceawere
Vulnerability Detail
CVE-2026-107935UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
gvproxy Arbitrary File Deletion Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 3h ago
- Vendor
- Red Hat
- Product
- Red Hat Build of Podman Desktop
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-10-09T10:16:37.497Z",
"pubdate": "2026-10-09T10:16:37.497Z",
"executiveSummary": "A critical path traversal vulnerability exists within the gvproxy network forwarder component of gvisor-tap-vsock. The vulnerability resides in the /services/forwarder/expose endpoint, which fails to adequately sanitize user-supplied input regarding socket paths.\nThis security flaw allows an unauthenticated, remote attacker to perform arbitrary file deletion operations on the underlying host system. Because the application processes path parameters without validation, an attacker can manipulate the input to escape intended directory constraints, potentially targeting sensitive host files or configuration files.\nThe risk implication is severe, as successful exploitation facilitates unauthorized filesystem modification, which could lead to service disruption, denial of service (DoS), or potentially assist in further privilege escalation scenarios depending on the permissions of the process running gvproxy.\nNo authentication is required to access the affected endpoint, significantly lowering the barrier to entry for potential adversaries. Remediation requires rigorous input validation and the implementation of path canonicalization routines to ensure that all requested operations remain strictly within authorized directories.",
"technicalDetails": "The vulnerability is categorized as a path traversal flaw located within the gvproxy component of gvisor-tap-vsock. The root cause of the issue is the improper neutralization of directory traversal sequences in the path parameters processed by the /services/forwarder/expose endpoint.\nIn the context of network forwarders, the /services/forwarder/expose endpoint is intended to facilitate the binding or management of virtual socket paths. However, the implementation does not verify that the provided socket path is constrained to a designated 'safe' directory. By injecting directory traversal sequences—such as '../'—into the request payload, an attacker can escape the intended root directory.\nThe exploitation flow proceeds as follows: First, an attacker identifies the network interface exposed by gvproxy. Second, the attacker crafts a malicious HTTP request directed at /services/forwarder/expose. Within the request body or parameters, the attacker specifies a file path containing traversal characters pointing to a target file on the host filesystem. Third, the internal logic of gvproxy receives this input and uses it in a system call or file operation (such as an unlink operation) without prior validation or canonicalization.\nBecause gvproxy operates with the privileges of the user running the service on the host, the operation is executed with those same privileges. If the service is running with elevated privileges, the impact of the deletion is catastrophic, enabling the removal of system binaries, logs, or critical configuration files.\nThe lack of authentication on the /services/forwarder/expose endpoint exposes the service to any network entity capable of reaching the gvproxy interface. This network exposure is particularly dangerous in environments where gvisor-tap-vsock is utilized to bridge network traffic between virtualized environments and the host, as the attacker may bridge these segments to achieve connectivity.\nPost-exploitation impact is characterized primarily by the loss of file integrity and potential service failure. By systematically deleting required application files or lock files, an attacker can induce a permanent denial-of-service state for the gvproxy service or other services relying on the target files. Furthermore, this vulnerability serves as a primitive for more complex attacks, as deleting specific lock files or state files might be a prerequisite for bypassing secondary security controls or resetting service states to a vulnerable configuration."
}