HIGH 7.5 GitHub
CVE-2026-57231
Podman: Malformed Image can trick podman run into leaking host environment variables into the container
## Summary
An container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched.
## Details
podman run allows `--env VAR1` or `--env V
Affected Products
- go/github.com/containers/podman/v5 < 5.8.4
- go/go.podman.io/podman/v6 < 6.0.0
- go/github.com/containers/podman/v4 <= 4.9.5
- go/github.com/containers/podman/v3 <= 3.4.7
- go/github.com/containers/podman/v2 <= 2.2.1
- go/github.com/containers/podman >= 1.8.1, < 5.8.4
References
- https://github.com/advisories/GHSA-4hq8-gpf5-8p68
- https://github.com/podman-container-tools/podman/security/advisories/GHSA-4hq8-gpf5-8p68
- https://nvd.nist.gov/vuln/detail/CVE-2026-57231
- https://github.com/podman-container-tools/podman/commit/6c431b73dbf8e4b20b778644d7a80caebd
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-09-24 via GitHub. Affected: go/github.com/containers/podman/v5 < 5.8.4, go/go.podman.io/podman/v6 < 6.0.0, go/github.com/containers/podman/v4 <= 4.9.5 and 3 more.
vulnfeed aggregates 11721 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.