{"id":"RHSA-2026:57590","summary":"Red Hat Security Advisory: rh-podman-desktop security, bug fix, and enhancement update","modified":"2026-08-24T10:18:31Z","published":"2026-08-21T10:14:02Z","upstream":["CVE-2026-9595","CVE-2026-12143","CVE-2026-13149","CVE-2026-13676","CVE-2026-14257","CVE-2026-34986","CVE-2026-42338","CVE-2026-42570","CVE-2026-44705","CVE-2026-45623","CVE-2026-45736","CVE-2026-45740","CVE-2026-48068","CVE-2026-48779","CVE-2026-48801","CVE-2026-49978","CVE-2026-56876","CVE-2026-59869","CVE-2026-59873","CVE-2026-59874","CVE-2026-59877","CVE-2026-69152","CVE-2026-69153","CVE-2026-69192"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:57590"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2455470"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2476810"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477081"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477914"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487050"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487946"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488480"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488934"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489661"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493633"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494197"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2494813"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498116"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498120"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498122"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498127"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2499682"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500656"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500695"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506433"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2507595"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510719"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510722"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2510801"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/RHEL-238929"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_57590.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-9595"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-9595"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9595"},{"type":"ARTICLE","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"ARTICLE","url":"https://github.com/facebook/create-react-app/pull/7444"},{"type":"ARTICLE","url":"https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb"},{"type":"ARTICLE","url":"https://github.com/webpack/webpack-dev-server/pull/4316"},{"type":"ARTICLE","url":"https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-12143"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-12143"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12143"},{"type":"ARTICLE","url":"https://cwe.mitre.org/data/definitions/93.html"},{"type":"ARTICLE","url":"https://github.com/form-data/form-data/commit/64190db548c0179e37206858e39f27cf513e9435"},{"type":"ARTICLE","url":"https://github.com/form-data/form-data/commit/be3f3cf553978bac15a5182f1f3c3d2d38ccf229"},{"type":"ARTICLE","url":"https://github.com/form-data/form-data/commit/c7133499c2ee1b80c678e411244f4442bf902045"},{"type":"ARTICLE","url":"https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx"},{"type":"ARTICLE","url":"https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#multipart-form-data"},{"type":"ARTICLE","url":"https://www.npmjs.com/package/form-data"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-13149"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-13149"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13149"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754"},{"type":"ARTICLE","url":"https://www.npmjs.com/package/brace-expansion"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-13676"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-13676"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-13676"},{"type":"ARTICLE","url":"https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14257"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14257"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14257"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-34986"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-34986"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34986"},{"type":"ARTICLE","url":"https://github.com/go-jose/go-jose/security/advisories/GHSA-78h2-9frx-2jm8"},{"type":"ARTICLE","url":"https://pkg.go.dev/github.com/go-jose/go-jose/v4#pkg-constants"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42338"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42338"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42338"},{"type":"ARTICLE","url":"https://github.com/beaugunderson/ip-address/security/advisories/GHSA-v2v4-37r5-5v8g"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-42570"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-42570"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42570"},{"type":"ARTICLE","url":"https://github.com/sveltejs/devalue/commit/206ca6712fbc380a4571c59de9ab04b91110792d"},{"type":"ARTICLE","url":"https://github.com/sveltejs/devalue/releases/tag/v5.8.1"},{"type":"ARTICLE","url":"https://github.com/sveltejs/devalue/security/advisories/GHSA-77vg-94rm-hx3p"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-44705"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-44705"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44705"},{"type":"ARTICLE","url":"https://github.com/raszi/node-tmp/security/advisories/GHSA-ph9p-34f9-6g65"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45623"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45623"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45623"},{"type":"ARTICLE","url":"https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45736"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45736"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45736"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/commit/c0327ec15a54d701eb6ccefaa8bef328cfc03086"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/security/advisories/GHSA-58qx-3vcg-4xpx"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45740"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45740"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45740"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-jggg-4jg4-v7c6"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48068"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48068"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48068"},{"type":"ARTICLE","url":"https://github.com/grpc/grpc-node/security/advisories/GHSA-5375-pq7m-f5r2"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48779"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48779"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48779"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/commit/86d3e8a5fb0246ed373860c5fbb0de88824a27f7"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/commit/b5372ac67bb97a773727b8e9f5035a8123556d53"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/commit/bca91adf15677e47dbe4f959653452727be28b94"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/commit/fd36cd864fcdf62a08273a99e19a7d975401fee8"},{"type":"ARTICLE","url":"https://github.com/websockets/ws/security/advisories/GHSA-96hv-2xvq-fx4p"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48801"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48801"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48801"},{"type":"ARTICLE","url":"https://github.com/markdown-it/linkify-it/commit/6be6d15e0641bf1daeaa977d500cabc743166159"},{"type":"ARTICLE","url":"https://github.com/markdown-it/linkify-it/security/advisories/GHSA-22p9-wv53-3rq4"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-49978"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-49978"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49978"},{"type":"ARTICLE","url":"https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff"},{"type":"ARTICLE","url":"https://github.com/cure53/DOMPurify/releases/tag/3.4.7"},{"type":"ARTICLE","url":"https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-56876"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-56876"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56876"},{"type":"ARTICLE","url":"https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf"},{"type":"ARTICLE","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-177-01.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59869"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59869"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59869"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/commit/24f13e79ee1343a7e30bd6f6c9d9cdbf0ac9b2b7"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/commit/59423c6f8cdc78742ac00e25a4dd39ef16b702e4"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/releases/tag/3.15.0"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/releases/tag/4.3.0"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/security/advisories/GHSA-52cp-r559-cp3m"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59873"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59873"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59873"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/commit/2812e9338665659b183aa7226518c307044957d3"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/releases/tag/v7.5.19"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-23hp-3jrh-7fpw"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59874"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59874"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59874"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/releases/tag/v7.5.18"},{"type":"ARTICLE","url":"https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5w"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59877"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59877"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59877"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/commit/10fba6d54815ceecca8a06b9a6db490c8f5d2217"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/commit/fa5c73add738ceb471e74da8cc2f3727c3d0a69f"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/pull/2352"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.6.5"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.6.6"},{"type":"ARTICLE","url":"https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-j3f2-48v5-ccww"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-69152"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-69152"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69152"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/139d015104e71433ad52a41d19467c48ecbb2c7d"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/1e30c930238d7162802d88a94189182def178dac"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/688a99eeaab02627c2b89ba8ba4821fecfa659cf"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/commit/cb4b9e47cc2ec777c14b2b4492fb431a56f6a031"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-rgw5-rvv9-x895"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-69153"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-69153"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69153"},{"type":"ARTICLE","url":"https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8"},{"type":"ARTICLE","url":"https://github.com/postcss/postcss/releases/tag/8.5.19"},{"type":"ARTICLE","url":"https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-69192"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-69192"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69192"},{"type":"ARTICLE","url":"https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e"},{"type":"ARTICLE","url":"https://github.com/beaugunderson/ip-address/releases/tag/v10.3.1"},{"type":"ARTICLE","url":"https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr"}],"affected":[{"package":{"name":"rh-podman-desktop","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/rh-podman-desktop"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:1.1.2-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:57590.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}