CVE-2026-57231Podman_project · Podman
Vulnerability data via NVD (ingested)
Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an asterisk (*) will cause podman to pass all host variables into the container. So essentially a malicious image can exfiltrate all podman environment variables that are set in the session from where the container is launched. This vulnerability is fixed in 5.8.4 and 6.0.0.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-57231product:"Podman Project Podman"http.html:"Podman"More intel sources (5)
vuln:CVE-2026-57231vulnerabilities.cve_id: CVE-2026-57231CVE-2026-57231CVE-2026-57231"CVE-2026-57231" exploit -site:nvd.nist.gov