Flatpak 1.18.1 fixes receive CVE identifiers from MITRE and Red Hat after GitHub CNA non-response
Flatpak maintainer Simon McVittie published CVE IDs for most vulnerabilities fixed in Flatpak 1.18.1 after GitHub's CNA failed to respond, and MITRE assigned two further IDs on 23 September; some identifiers were still pending and no impact details were given.
Flatpak maintainer Simon McVittie announced on oss-security on 2026-09-22 that CVE identifiers had been obtained for most of the vulnerabilities fixed in Flatpak 1.18.1, after requests to GitHub as CNA drew no response and were redirected to MITRE and Red Hat. The published IDs are CVE-2026-90616, CVE-2026-96275, CVE-2026-96276, CVE-2026-96279, and CVE-2026-92162; at that time two identifiers remained pending, including MITRE candidate reference CAN-2026-2052453, with others requested from Red Hat. On 2026-09-23 McVittie reported that MITRE assigned CVE-2026-96808, mapping to GHSA-qrwq-7qwx-q9rp, and CVE-2026-96807, mapping to GHSA-99wv-m8rp-g58x, both covering issues fixed in Flatpak 1.18.1. The two posts do not contradict each other, but neither explicitly states that these two IDs close out the earlier pending set or resolve CAN-2026-2052453. Neither message describes impact or exploitation; both are administrative CVE-mapping follow-ups.
- Flatpak 1.18.1 fixed multiple vulnerabilities; CVE IDs for most of them were announced on 2026-09-22 by maintainer Simon McVittie on oss-security.
- Requests for IDs initially went to GitHub as CNA before unembargoing, but drew no response, so they were redirected to MITRE and Red Hat.
- IDs assigned via that route: CVE-2026-90616, CVE-2026-96275, CVE-2026-96276, CVE-2026-96279, CVE-2026-92162.
- As of 2026-09-22, two identifiers remained pending: one from MITRE (candidate ref CAN-2026-2052453) and others requested from Red Hat.
- On 2026-09-23, MITRE assigned CVE-2026-96808 (GHSA-qrwq-7qwx-q9rp) and CVE-2026-96807 (GHSA-99wv-m8rp-g58x) for issues fixed in Flatpak 1.18.1.
- Neither report states whether the 23 September IDs resolve the pending identifiers or CAN-2026-2052453.
- Neither report describes impact or exploitation; both are administrative CVE-mapping announcements.
Coverage timelineoldest first · each row is one article
- · 4d agoRe: Flatpak 1.18.1 fixes multiple vulnerabilities
oss-security· 38
Simon McVittie disclosed CVE identifiers for multiple vulnerabilities fixed in Flatpak 1.18.1, with two IDs still pending from MITRE.
- · 3d agoRe: Flatpak 1.18.1 fixes multiple vulnerabilities
oss-security· 32
MITRE assigned CVE-2026-96808 and CVE-2026-96807 to Flatpak flaws fixed in 1.18.1.
Vulnerabilities in this storyAll →
- CVE-2026-906167.4—Symlink escape in Flatpak before 1.18.1 lets sandboxed apps read/write host filespublished · Flatpak
- published — PoC