Description
A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Unauthorized Host File Deletion
Action: Immediate Patch
AI Analysis

Impact

gvproxy, the network forwarder provided by the gvisor‑tap‑vsock package, contains a path traversal flaw that allows an unauthenticated attacker to delete arbitrary files on the host. The /services/forwarder/expose endpoint does not validate the caller‑supplied socket path, enabling deletion of any file. This vulnerability can lead to loss of critical system files, interruption of services, and potentially provide a foothold for further exploitation. The weakness is a classic directory traversal flaw (CWE‑22).

Affected Systems

The affected products are all Red Hat‑branded environments that ship the gvisor‑tap‑vsock package, including the Red Hat Build of Podman Desktop, Red Hat Certification Program for RHEL 9, Red Hat Edge Manager 1, Red Hat Enterprise Linux 8, 9, 10, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces, and Red Hat OpenStack Platform 18.0. Version information is not specified, so any derivative using the vulnerable gvproxy component is potentially impacted.

Risk and Exploitability

The CVSS score of 9.3 places this flaw in the high‑severity range, and because the attacker does not need authentication the vulnerability is trivially exploitable over the network. Although the EPSS score is not available, the lack of authentication combined with the high damage potential means that exploitation is likely if an attacker can reach the exposed endpoint. Red Hat has not listed the flaw in the CISA KEV catalog, but the lack of a remedy in the advisory indicates urgent patching is required.

Generated by OpenCVE AI on October 9, 2026 at 10:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest gvisor‑tap‑vsock package that includes the security patch
  • Disable or restrict access to the /services/forwarder/expose endpoint using firewall rules or by binding it to localhost only
  • Configure containers to use validated socket paths and enforce strict path checks in the host environment

Generated by OpenCVE AI on October 9, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.
Title Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via /expose
First Time appeared Redhat
Redhat certifications
Redhat edge Manager
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat openshift Devspaces
Redhat openstack
Redhat podman Desktop
Weaknesses CWE-22
CPEs cpe:/a:redhat:certifications:9
cpe:/a:redhat:edge_manager:1
cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_devspaces:3
cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:podman_desktop:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat certifications
Redhat edge Manager
Redhat enterprise Linux
Redhat hummingbird
Redhat openshift
Redhat openshift Devspaces
Redhat openstack
Redhat podman Desktop
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Redhat Certifications Edge Manager Enterprise Linux Hummingbird Openshift Openshift Devspaces Openstack Podman Desktop
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-09T09:05:43.726Z

Reserved: 2026-10-09T08:27:11.041Z

Link: CVE-2026-107935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:37.497

Modified: 2026-10-09T10:16:37.497

Link: CVE-2026-107935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T10:45:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')