Skip to content
Saturday, October 10, 2026AboutContactRSS
Unauthenticated gvproxy Endpoint Enables Arbitrary Host File Deletion
Vulnerabilities

Unauthenticated gvproxy Endpoint Enables Arbitrary Host File Deletion

A critical path traversal flaw in gvproxy allows attackers to delete files on the host system via an unvalidated socket path parameter.

Key points

  • CVE-2026-107935 is rated Critical with a CVSS score of 9.3 due to unauthenticated access.
  • The vulnerability resides in the /services/forwarder/expose endpoint of the gvisor-tap-vsock package.
  • Red Hat lists multiple enterprise products, including Podman Desktop and RHEL 10, as affected.

A severe path traversal vulnerability in gvproxy allows attackers to delete arbitrary files on a host system without authentication. The flaw, tracked as CVE-2026-107935, stems from insufficient validation of user-supplied data in a network forwarding service.

What happened

The vulnerability exists in gvproxy, the network forwarder component included in the gvisor-tap-vsock package. According to the National Vulnerability Database (NVD), the issue arises because the unauthenticated /services/forwarder/expose endpoint fails to properly validate the socket path provided by the caller. An attacker who can send requests to this endpoint can manipulate the path parameter to traverse directory structures and delete any file on the underlying host system. The NVD assigns a CVSS score of 9.3 to CVE-2026-107935, classifying it as a Critical severity vulnerability. The weakness is categorized under CWE-22, indicating improper limitation of a pathname to a restricted directory. Because the endpoint is unauthenticated, an attacker does not need valid credentials to exploit the flaw, significantly lowering the barrier to entry for malicious activity.

Why it matters

This vulnerability poses a direct threat to the integrity of systems relying on the affected software. The NVD records indicate that Red Hat has identified several of its products as affected by this flaw. These include Red Hat Build of Podman Desktop, the Red Hat Certification Program for Red Hat Enterprise Linux 9, Red Hat Edge Manager 1, and Red Hat Enterprise Linux 10. The impact extends to multiple versions of RHEL 10, suggesting a broad attack surface within enterprise environments using these platforms. For IT managers and CISOs, the ability to delete arbitrary host files can lead to severe operational disruption, data loss, or the disabling of security controls. The unauthenticated nature of the exploit means that any network access to the vulnerable endpoint could result in a successful attack, making network segmentation and access controls critical mitigation strategies until a fix is available.

What to watch

  • Monitor network traffic for unusual requests to the /services/forwarder/expose endpoint.
  • Check system logs for unexpected file deletions or permission errors on the host system.
  • Review access controls to ensure the vulnerable endpoint is not exposed to untrusted networks.
  • Keep an eye on vendor advisories for Red Hat and gvisor-tap-vsock for patch releases.

What to do and how to stay safe: gvproxy

  • Restrict network access to the gvproxy service to trusted internal networks only, blocking external connections to the exposed endpoint.
  • Implement strict firewall rules to deny traffic to the /services/forwarder/expose endpoint from untrusted sources until a patch is released.
  • Monitor host file integrity using intrusion detection systems to alert on unauthorized deletions or modifications.
  • Once the vendor provides an update, apply the patch immediately to remediate the path traversal vulnerability.

General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is CVE-2026-107935?

It is a critical path traversal vulnerability in gvproxy that allows unauthenticated attackers to delete arbitrary files on the host system.

Which Red Hat products are affected?

Affected products include Red Hat Build of Podman Desktop, Red Hat Certification Program for RHEL 9, Red Hat Edge Manager 1, and Red Hat Enterprise Linux 10.

Is authentication required to exploit this flaw?

No, the /services/forwarder/expose endpoint is unauthenticated, allowing attackers to exploit it without valid credentials.

Sources

  1. CVE Program
  2. NVD
gvproxyCVE-2026-107935Red Hatgvisor-tap-vsockpath traversal

Related stories

Parameterized Queries Mistakes That Leave Databases Exposed

Most SQL injection flaws persist because developers treat parameterized queries as a magic shield rather than a strict syntax rule with rigid boundaries.