
🚨High - rpm Code Execution via Manifest Macro Expansion (CVE-2026-95519) rpm processes crafted manifest files via rpm -q -p (and similar query/manifest flows) where manifest entries are macro-expanded before open(), allowing embedded shell commands to execute with rpm’s privileges. This yields arbitrary code execution impacting CIA. 👉Affected: rpm (versions TBD)
