Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Syncing distribution trees only from a trusted upstream avoids a crafted .treeinfo from that source. An account that can upload a tree directly can still supply the file. Otherwise, Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 07 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service. | |
| Title | Pulp-rpm: distribution tree publish creates directories from .treeinfo ids | |
| First Time appeared |
Redhat
Redhat rhui Redhat satellite |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:rhui:4::el8 cpe:/a:redhat:rhui:5::el9 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat rhui Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T19:28:12.925Z
Reserved: 2026-10-01T11:51:10.972Z
Link: CVE-2026-103870
No data.
Status : Awaiting Analysis
Published: 2026-10-07T06:16:35.373
Modified: 2026-10-07T14:47:21.140
Link: CVE-2026-103870
OpenCVE Enrichment
Updated: 2026-10-07T07:45:14Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')