This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Containers & Orchestration
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
containers
docker
kubernetes
linux
Affected surfaces
rce_ssrf
Summary
AI summaryCVE-2026-57231 fixes environment variable leakage in containers and updates golang.org/x/crypto to address CVE-2026-39830, CVE-2026-42508.
Full changelog
Security
- This release addresses CVE-2026-57231, where a malicious image using malformed
Enventries could cause host environment variables to leak into containers run based on the image, including the ability to use the*glob operator to leak large numbers of environment variables without knowing their exact names (GHSA-4hq8-gpf5-8p68). - The golang.org/x/crypto library has been updated to v0.53.0, addressing CVE-2026-39830 and CVE-2026-42508.
Bugfixes
- Fixed a bug where the remote Podman client's
podman savecommand would fail on Linux when using the-f oci-diror-f docker-dirarguments.
Security Fixes
- CVE-2026-57231 — malicious image `Env` entries leak host environment variables into containers, allowing glob-based leakage ([GHSA-4hq8-gpf5-8p68])
- dep: CVE-2026-39830 addressed by updating golang.org/x/crypto to v0.53.0
- dep: CVE-2026-42508 addressed by updating golang.org/x/crypto to v0.53.0
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]