
A developer tool on your network just became a remote attack vector 🌐 Pentera Labs researcher Nir Chako discovered CVE-2026-34045 in Podman Desktop, a tool with 3M+ downloads and a fresh spot in the CNCF Sandbox. The issue? A background service intended for localhost was silently binding to port 44000 on all network interfaces. No authentication. No connection limits. No timeouts. That's all an attacker needs. With just network access, a remote unauthenticated attacker could: → Crash the host entirely using a Slowloris-style connection flood → Extract internal usernames and filesystem paths from unhandled error responses As always, the emerging technologies of today are the mainstream of tomorrow. It’s better to close the security issues at this stage, before the blast radius becomes too big to handle. OWASP's Top 10:2025 now officially ranks developer workstations among the most critical attack surface areas in the software supply chain. This CVE is a live example of exactly why. If you're running Podman Desktop, update to v1.26.2 (or newer) now. Full research here👇 https://okt.to/xsCqVg
Post summary
CVE-2026-34045 in Podman Desktop exposes a background service with no authentication listening on port 44000, enabling remote unauthenticated attacks such as denial‑of‑service and data leaks, and users are advised to update to v1.26.2 or newer.



