CVE detail
CVE-2026-15809
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://github.com/cri-o/cri-o/pull/6524github.com
No excerpt available.
Exploitgithub.comJul 15, 2026, 1:17 PM - https://github.com/cri-o/cri-o/pull/6450github.com
No excerpt available.
Exploitgithub.comJul 15, 2026, 1:17 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2500846bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJul 15, 2026, 1:17 PM - https://access.redhat.com/security/cve/cve-2022-4318access.redhat.com
No excerpt available.
Exploitaccess.redhat.comJul 15, 2026, 1:17 PM - https://access.redhat.com/security/cve/CVE-2026-15809access.redhat.com
No excerpt available.
Exploitaccess.redhat.comJul 15, 2026, 1:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73479CVSS 4.8 · Medium
dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names containing OSC/CSI escape sequenc…
- CVE-2026-73417CVSS 8.6 · High
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allow…
- CVE-2026-73480CVSS 4.8 · Medium
gdu fails to strip terminal escape sequences from directory and file names when printing paths after TUI exit. Attackers can craft malicious directory or file names containing esc…
- CVE-2025-62315CVSS 3.4 · Low
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the appli…
- CVE-2026-73411CVSS 6.3 · Medium
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~ after : or = when application…
- CVE-2026-12004CVSS 8.7 · High
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format…