Junglewise Threat Intelligence

CVE-2026-34045: Podman Desktop DoS and information disclosure in WebView server

CVE-2026-34045 · Severity: high · CVSS 8.2 · Published 2026-04-07

Technologies: Red Hat Enterprise Linux 10, Red Hat Build of Podman Desktop - Tech Preview. Vendors: Red Hat, Linuxfoundation.

Executive brief

Podman Desktop is a graphical application used by developers to manage containers and Kubernetes environments. A security flaw allows remote attackers to crash the application or freeze the entire computer by flooding an unprotected internal web server with connections. Additionally, the application may leak sensitive system information, such as internal file paths and Windows usernames, which could be used to plan further attacks.

Technical details

Podman Desktop's WebView HTTP server, listening on port 44000, was found to bind to all network interfaces (0.0.0.0) without authentication, connection limits, or request timeouts. A remote attacker can exploit this by initiating a connection flood (Slowloris-style attack), exhausting file descriptors and kernel memory, which leads to application crashes or full host freezes. Furthermore, the server's verbose error responses disclose internal file paths and, on Windows systems, the current user's username. The vulnerability is resolved in version 1.26.2 by binding the server to the loopback interface (127.0.0.1) and implementing resource limits.

Affected products

  • Red Hat Podman Desktop < 1.26.2
  • Red Hat Red Hat Enterprise Linux 10 10.1

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-04-07: patched: Fixed in version 1.26.2

References