CVE-2026-107935 is a critical (CVSS 9.3) path traversal flaw in gvproxy, part of the gvisor-tap-vsock package, that lets an unauthenticated attacker delete arbitrary files on the host system.
What Is It
gvproxy is the network forwarder provided by the gvisor-tap-vsock package. Its /services/forwarder/expose endpoint requires no authentication. It also does not validate the socket path the caller supplies. An attacker can abuse this to delete arbitrary files on the host. The weakness is classified as CWE-22 (Path Traversal).
Red Hat ([email protected]) assigned the CVE, and NVD published it on 2026-10-09. The NVD record currently has the status "Received."
Why It Matters
Red Hat scores this issue 9.3 (CRITICAL) with the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H. In practice:
- Adjacent network access: the attacker must be on an adjacent network, not just anywhere on the internet.
- Easy to exploit: attack complexity is low, and no privileges or user interaction are needed.
- Changed scope: the impact reaches past the vulnerable component to the host system.
- High integrity and availability impact: arbitrary file deletion on the host can damage system integrity and cause outages.
The CISA KEV catalog has no entry for this CVE, so active exploitation is not confirmed in the supplied data.
What's Vulnerable
Red Hat marks two products as affected:
- Red Hat Build of Podman Desktop (
rh-podman-desktop) - Red Hat OpenShift Dev Spaces (
devspaces/udi-base-rhel10)
Red Hat lists these products and packages with an unknown status, still under assessment:
- Red Hat Enterprise Linux 8:
container-tools:rhel8/podman - Red Hat Enterprise Linux 9:
gvisor-tap-vsock,podman - Red Hat Enterprise Linux 10:
gvisor-tap-vsock,podman,ubi10/podman,rhel10/rhel-bootc,rhel10/bootc-image-builder,rhel10-eus/rhel-10.0-bootc,rhel10-eus/rhel-10.2-bootc - Red Hat OpenShift Container Platform 4:
podman,openshift4/microshift-bootc-rhel10 - Red Hat Edge Manager 1, Red Hat Hardened Images, Red Hat Certification Program for RHEL 9, and Red Hat OpenStack Platform 18.0 (podman-related packages)
Patch Status
The supplied NVD data lists no fixed versions or vendor advisories. The references include an upstream gvisor-tap-vsock pull request (#718), a Red Hat Bugzilla entry, and a Red Hat tracker ticket. There is no KEV entry, so no CISA required action or due date applies.
Watch the Red Hat CVE page for errata covering your installed packages, and apply updates when they are released.