CVE-2026-58015
ADVISORY - debianSummary
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
- glib2.0 2.88.1-2 [trixie] - glib2.0 (Minor issue) [bookworm] - glib2.0 (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server) [bullseye] - glib2.0 (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server) https://gitlab.gnome.org/GNOME/glib/-/work_items/3931 https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5172 (2.89.0) https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
EPSS Score: 0.00418 (0.342)
Common Weakness Enumeration (CWE)
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in