{"api_version":"v1","generated_at":"2026-10-06T12:50:00+00:00","product":{"cve_count":11,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-flatpak-flatpak-904ded210e07","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Flatpak","next_cursor":null,"observations":[{"affected":"Flatpak: < 1.18.1","affected_versions_present":true,"cve_id":"CVE-2026-96808","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96808","fixed":"Fixed in 1.18.1 by commits:; * a3583bc https://github.com/flatpak/flatpak/commit/a3583bc87d4f86c2794ff879ea56fce95b0b0b5f \"revokefs: Avoid symlink path traversal out of basefd in simple cases\"; * b00c7b5 https://github.com/flatpak/flatpak/commit/b00c7b5073a25bdc34653642de543b5ef6fe0225 \"revokefs: Avoid symlink path traversal in link(), rename()\"; * 4ddb5dc https://github.com/flatpak/flatpak/commit/4ddb5dc0de1bd25e52627f520a49063d94f79377 \"revokefs: Avoid symlink path traversal in symlink()\"; * e7f96b4 https://github.com/flatpak/flatpak/commit/e7f96b4d1533f735ace2ea21dbf770e8d4be465a \"revokefs: Avoid symlink path traversal in chmod()\"; For LTS operating system distributions, backports of these changes are available in the flatpak-1.16.x branch.","last_modified":"2026-09-23T18:22:46.208Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp","primary_source":"","published":"2026-09-23T16:58:37.139Z"},{"affected":"Flatpak: < 1.18.1","affected_versions_present":true,"cve_id":"CVE-2026-96807","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-96807","fixed":"The issue has been fixed in version 1.18.1 by commits:; * e13dfed https://github.com/flatpak/flatpak/commit/e13dfeda330625d2fecc3a54672dfd4dc9c83a5c \"common: Fix return value and typos in flatpak_switch_symlink_and_remove\"; * f6c8fb5 https://github.com/flatpak/flatpak/commit/f6c8fb5fdb3737e2f45068afe12c4bf1d808fd55 \"common: Use fd-based operations in flatpak_switch_symlink_and_remove\"; * 76c9296 https://github.com/flatpak/flatpak/commit/76c9296b6780ca67f44cf67f0823f086d692a592 \"run: Harden regenerate_ld_cache against symlink attacks\"; For LTS operating system distributions, backports of these changes are available in the flatpak-1.16.x; branch. Please note that cherry-picked libglnx changes \"chase: Add; internal glnx_chaseat_full for a strategic callback\" and \"chase: Add; glnx_chase_and_mkdirat\" are also required.","last_modified":"2026-09-26T22:51:21.873Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x","primary_source":"","published":"2026-09-23T16:54:16.931Z"},{"affected":"Flatpak: < 1.18.1","affected_versions_present":true,"cve_id":"CVE-2026-90616","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90616","fixed":"https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e","last_modified":"2026-09-14T18:22:31.917Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj","primary_source":"","published":"2026-09-12T20:00:58.476Z"},{"affected":"< 1.16.4","affected_versions_present":true,"cve_id":"CVE-2026-34079","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34079","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-10T20:13:47.945Z","patch_url":"","primary_source":"","published":"2026-04-07T21:29:44.601Z"},{"affected":"< 1.16.4","affected_versions_present":true,"cve_id":"CVE-2026-34078","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34078","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:04:42.753Z","patch_url":"","primary_source":"","published":"2026-04-07T21:27:45.643Z"},{"affected":"< 1.14.10; >= 1.15.0, < 1.15.10","affected_versions_present":true,"cve_id":"CVE-2024-42472","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-42472","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-02T22:03:10.874Z","patch_url":"https://github.com/containers/bubblewrap/commit/68e75c3091c87583c28a439b45c45627a94d622c","primary_source":"","published":"2024-08-15T18:32:11.304Z"},{"affected":"< 1.10.9; >= 1.12.0, < 1.12.9; >= 1.14.0, < 1.14.6; >= 1.15.0, < 1.15.8","affected_versions_present":true,"cve_id":"CVE-2024-32462","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-32462","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-12-16T18:13:22.363Z","patch_url":"https://github.com/flatpak/flatpak/commit/72016e3fce8fcbeab707daf4f1a02b931fcc004d","primary_source":"","published":"2024-04-18T18:11:27.680Z"},{"affected":"< 1.10.8; >= 1.12.0, < 1.12.8; >= 1.14.0, < 1.14.4; >= 1.15.0, < 1.15.4","affected_versions_present":true,"cve_id":"CVE-2023-28101","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28101","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-25T14:55:35.911Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-h43h-fwqx-mpp8","primary_source":"","published":"2023-03-16T15:55:53.576Z"},{"affected":"< 1.10.8; >= 1.12.0, < 1.12.8; >= 1.14.0, < 1.14.4; >= 1.15.0, < 1.15.4","affected_versions_present":true,"cve_id":"CVE-2023-28100","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-28100","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:45:39.112Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-7qpw-3vjv-xrqp","primary_source":"","published":"2023-03-16T15:51:32.037Z"},{"affected":">= 1.11.0, < 1.12.3; < 1.10.6","affected_versions_present":true,"cve_id":"CVE-2022-21682","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-21682","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T02:46:39.409Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx","primary_source":"","published":"2022-01-13T00:00:00.000Z"},{"affected":">= 1.11.0, < 1.12.3; < 1.10.6","affected_versions_present":true,"cve_id":"CVE-2021-43860","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-43860","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T04:10:17.171Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-qpjc-vq3c-572j","primary_source":"","published":"2022-01-12T00:00:00.000Z"},{"affected":">= 1.8.0, <= 1.8.2; >= 1.10.0, < 1.10.4; >= 1.11.0, < 1.12.0","affected_versions_present":true,"cve_id":"CVE-2021-41133","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41133","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T02:59:31.388Z","patch_url":"https://github.com/flatpak/flatpak/security/advisories/GHSA-67h7-w3jq-vh4q","primary_source":"","published":"2021-10-08T00:00:00.000Z"},{"affected":">= 0.9.4, < 1.10.2","affected_versions_present":true,"cve_id":"CVE-2021-21381","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21381","fixed":"1.10.2.","last_modified":"2024-08-03T18:09:15.945Z","patch_url":"https://github.com/flatpak/flatpak/pull/4156","primary_source":"","published":"2021-03-11T00:00:00.000Z"},{"affected":">= 0.11.4, < 1.8.5; >= 1.9.0, < 1.10.0","affected_versions_present":true,"cve_id":"CVE-2021-21261","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21261","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:14.989Z","patch_url":"https://github.com/flatpak/flatpak/commit/6d1773d2a54dde9b099043f07a2094a4f1c2f486","primary_source":"","published":"2021-01-14T19:40:21.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Flatpak"}}
