Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 80%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Medium
Published: 07/22/2026 (07/22/2026, 01:01:59 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

CVE-2026-15788 is a medium severity vulnerability in BuildKit used by Red Hat Hardened Images. It allows an untrusted user authoring a build on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system due to improper handling of NTFS directory junctions, leading to information disclosure. The issue is related to a path traversal flaw (CWE-22). Red Hat has released updated RPM packages including buildah-1.44.0-3.2.hum1 to address this vulnerability.

Affected software

redhat/buildah
pkg:rpm/redhat/buildah
Affected versions
=1.44.0-3.2.hum1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/06/2026, 18:43:26 UTC

Technical Analysis

This vulnerability (CVE-2026-15788) affects BuildKit in Red Hat Hardened Images. An untrusted user can exploit a flaw in the cache mount source selector on a Windows Container on Windows (WCOW) configured BuildKit daemon to read arbitrary files from the host system. The root cause is improper limitation of pathnames leading to a path traversal (CWE-22). This results in information disclosure without requiring privileges or user interaction. Red Hat has issued a security advisory (RHSA-2026:43122) with updated buildah RPMs to fix this issue.

Potential Impact

An attacker with the ability to author builds on a vulnerable BuildKit daemon configured for WCOW can read arbitrary files on the host system, leading to confidentiality breaches. There is no impact on integrity or availability reported. The vulnerability does not require privileges or user interaction, but the attack vector is local to the BuildKit daemon environment. No known exploits in the wild have been reported.

Mitigation Recommendations

Red Hat has released updated RPM packages (buildah-1.44.0-3.2.hum1 and buildah-tests-1.44.0-3.2.hum1) that address this vulnerability. Users should apply these updates promptly to remediate the issue. No additional mitigations or workarounds are specified in the vendor advisory. Patch status is confirmed by Red Hat's official advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:43122
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a74cf8fbf8831d5391aef0f

Added to database: 08/06/2026, 18:16:47 UTC

Last enriched: 08/06/2026, 18:43:26 UTC

Last updated: 08/07/2026, 03:40:59 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses