CVE-2026-34045Disclosure(linuxfoundation / podman_desktop)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation podman_desktop systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any network attacker to remotely trigger denial-of-service conditions and extract sensitive information. By abusing missing connection limits and timeouts, an attacker can exhaust file descriptors and kernel memory, leading to application crash or full host freeze. Additionally, verbose error responses disclose internal paths and system details (including usernames on Windows), aiding further exploitation. The issue requires no authentication or user interaction and is exploitable over the network. This vulnerability is fixed in 1.26.2.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209CWE-284CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • podman_desktop

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-08); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
podman_desktop

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-08: 2Mentions · 2026-05-21: 1Mentions · 2026-06-23: 1PoC Mentioned / Linked · 2026-06-23: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-04-08: 2Technical Details · 2026-05-21: 1Technical Details · 2026-06-23: 104-0805-2106-23
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure1General1
2026-05-211
Disclosure1
2026-06-231
Disclosure1
Full discourse4 posts
  • Pentera@penterasec
    Disclosure

    A developer tool on your network just became a remote attack vector 🌐 Pentera Labs researcher Nir Chako discovered CVE-2026-34045 in Podman Desktop, a tool with 3M+ downloads and a fresh spot in the CNCF Sandbox. The issue? A background service intended for localhost was silently binding to port 44000 on all network interfaces. No authentication. No connection limits. No timeouts. That's all an attacker needs. With just network access, a remote unauthenticated attacker could: → Crash the host entirely using a Slowloris-style connection flood → Extract internal usernames and filesystem paths from unhandled error responses As always, the emerging technologies of today are the mainstream of tomorrow. It’s better to close the security issues at this stage, before the blast radius becomes too big to handle.  OWASP's Top 10:2025 now officially ranks developer workstations among the most critical attack surface areas in the software supply chain. This CVE is a live example of exactly why. If you're running Podman Desktop, update to v1.26.2 (or newer) now. Full research here👇 https://okt.to/xsCqVg

    Post summary

    CVE-2026-34045 in Podman Desktop exposes a background service with no authentication listening on port 44000, enabling remote unauthenticated attacks such as denial‑of‑service and data leaks, and users are advised to update to v1.26.2 or newer.

    00010159
    3.3K followersView on X
  • Sion Retzkin@SionRetz
    Disclosure

    A serious security flaw has been found in Podman Desktop, impacting over 3M users. @Nir Chako from Pentera Labs disclosed CVE-2026-34045, allowing local services to bind to port 44000 on all interfaces without authentication. Full research here: https://okt.to/xTME8a https://t.co/iEihkWzHz3

    Post summary

    The tweet discloses CVE‑2026‑34045, detailing its effect on Podman Desktop and links to research, but does not provide exploit code, reports active exploitation, or mention a patch.

    0000052
    41 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34045 Unauthenticated Denial-of-Service and Information Disclosure in Podman Desktop Before 1.26.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34045

    Post summary

    The post announces CVE-2026-34045, describing an unauthenticated DoS and information disclosure in Podman Desktop prior to version 1.26.2, without providing PoC, exploit code, or patch information.

    0000053
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34045 Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP server exposed by Podman Desktop allows any n… https://www.cve.org/CVERecord?id=CVE-2026-34045

    Post summary

    CVE‑2026‑34045 is an unauthenticated HTTP server issue in Podman Desktop prior to v1.26.2; the brief notice provides the vulnerability detail but no evidence of PoC, exploit code, active exploitation, or patch information.

    00000169
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationpodman_desktop---

Explore more