Re: Flatpak 1.18.1 fixes multiple vulnerabilities
Simon McVittie disclosed CVE identifiers for multiple vulnerabilities fixed in Flatpak 1.18.1, with two IDs still pending from MITRE.
Flatpak maintainer Simon McVittie announced that CVE IDs have finally been obtained for most of the vulnerabilities fixed in Flatpak 1.18.1, after GitHub's CNA failed to respond to requests. Assigned IDs include CVE-2026-90616, CVE-2026-96275, CVE-2026-96276, CVE-2026-96279, and CVE-2026-92162. Two identifiers remain pending, including one requested from MITRE (candidate ref CAN-2026-2052453), with others requested from Red Hat.
- Flatpak 1.18.1 fixed multiple vulnerabilities; CVE IDs now published
- GitHub CNA was unresponsive; IDs obtained via MITRE and Red Hat
- Two CVE identifiers remain pending, including CAN-2026-2052453
Vulnerabilities mentionedAll →
- CVE-2026-906167.4—Symlink escape in Flatpak before 1.18.1 lets sandboxed apps read/write host filespublished · Flatpak
- published — PoC
Posted by Simon McVittie on Sep 22 We've eventually been able to obtain CVE IDs for most of these (two are still pending). I requested CVE IDs from Github before we unembargoed, but we haven't received any response in most cases, so we fell back to requesting CVE IDs from other CNAs (variously MITRE and Red Hat). CVE-2026-90616 CVE ID requested from MITRE, pending request ref. CAN-2026-2052453 CVE-2026-96275 CVE-2026-96276 CVE-2026-96279 CVE-2026-92162...
This source does not provide full text. Read it at seclists.org.