GHSA-65gg-3w2w-hr4h

    Dashboard / Vulnerabilities / GHSA-65gg-3w2w-hr4h

    GHSA-65gg-3w2w-hr4h

    Published: 25 Jun 2025Last Modified: 10 Sept 2026

    Summary: Podman Improper Certificate Validation; machine missing TLS verification

    Details: ### Impact The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack. ### Patches https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3 Fixed in v5.5.2 ### Workarounds Download the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)

    Affected packages

    Package

    Name: github.com/containers/podman/v4

    Purl: pkg:golang/github.com/containers/podman/v4

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 4.8.0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-65gg-3w2w-hr4h | CVE-DB