Insecure Pull Management in Flatpak by Red Hat
CVE-2026-96283
3.3LOW
What is CVE-2026-96283?
This vulnerability in Flatpak allows a user to cancel an ongoing pull operation initiated by another user. However, the operation does not get cancelled; instead, it is merely removed from the internal tracking system. As a result, the original user cannot halt their ongoing pull, which could lead to potential resource exhaustion or denial of service. This flaw affects the ability of users to manage their application pulls effectively and securely.
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Asim Viladi Oglu Manizada as the original reporter.