Environment Variable Exposure in Podman (CVE-2026-57231)
39097
02 October 2026
02 October 2026
CLOSED
LOW
7.5
CVE-2026-57231
|
Brocade Security Advisory ID |
BSA-2026-3858 |
|
Component |
Podman |
Brocade Assessed Risk: LOW
Affected CVE ID: CVE-2026-57231
Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CWE-668 Exposure of Resource to Wrong Sphere
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Brocade Security Advisory ID: BSA-2026-3858
Summary:
A security vulnerability exists in Podman (versions 1.8.1 through 5.8.3) related to the improper handling of environment variables. Container images defined with an environment variable key but no value can trick Podman into inheriting that variable from the host. Furthermore, the use of an asterisk (*) wildcard causes Podman to inadvertently pass all host environment variables into the container.
Impact
This flaw allows a malicious container image to exfiltrate sensitive environment variables from the host session where the container is initiated. This potentially leads to unauthorized disclosure of environment-specific configuration data or secrets.
Product Affected
- Brocade SANnav before 3.0.1a
Product Not Affected
- Brocade Fabric OS: Component_not_present
- Brocade ASCG: Vulnerable_code_not_in_execute_path
Products Affected
Solution
- Although Brocade ASCG is not affected, a security update is provided in Brocade ASCG 3.5.0
- Security update provided in Brocade SANnav 3.0.1a
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
9/30/2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.