Cyber & AI intelligence
Wasteland.
Briefs indexed3100
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107935 2026-10-09

gvproxy Path Traversal Flaw Lets Unauthenticated Attackers Delete Host Files (CVE-2026-107935)

"CVE-2026-107935 is a critical (CVSS 9.3) path traversal flaw in gvproxy, part of the gvisor-tap-vsock package, that lets an unauthenticated attacker delete arbitrary files on the host system."

CVE-2026-107935 is a critical (CVSS 9.3) path traversal flaw in gvproxy, part of the gvisor-tap-vsock package, that lets an unauthenticated attacker delete arbitrary files on the host system.

What Is It

gvproxy is the network forwarder provided by the gvisor-tap-vsock package. Its /services/forwarder/expose endpoint requires no authentication. It also does not validate the socket path the caller supplies. An attacker can abuse this to delete arbitrary files on the host. The weakness is classified as CWE-22 (Path Traversal).

Red Hat ([email protected]) assigned the CVE, and NVD published it on 2026-10-09. The NVD record currently has the status "Received."

Why It Matters

Red Hat scores this issue 9.3 (CRITICAL) with the vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H. In practice:

The CISA KEV catalog has no entry for this CVE, so active exploitation is not confirmed in the supplied data.

What's Vulnerable

Red Hat marks two products as affected:

Red Hat lists these products and packages with an unknown status, still under assessment:

Patch Status

The supplied NVD data lists no fixed versions or vendor advisories. The references include an upstream gvisor-tap-vsock pull request (#718), a Red Hat Bugzilla entry, and a Red Hat tracker ticket. There is no KEV entry, so no CISA required action or due date applies.

Watch the Red Hat CVE page for errata covering your installed packages, and apply updates when they are released.

Sources