Red Hat released multiple Important security updates for Podman across Red Hat Enterprise Linux 9 and 10 product streams after identifying vulnerabilities inherited from bundled or dependent Go components. The advisories cover RHEL 9, RHEL 9.4 support channels, RHEL 10.0 Extended Update Support, and RHEL 10, with fixed builds including podman-5.6.0-14.el9_7, podman-4.9.4-20.el9_4.2, podman-5.4.0-15.el10_0.1, and podman-5.8.2-1.el10_2 for x86_64, s390x, ppc64le, and aarch64 systems. Red Hat said the issues could lead to denial of service, excessive CPU consumption, memory exhaustion, incorrect URL or IPv6 host parsing, and improper TLS session resumption certificate validation.
One of the highlighted flaws, CVE-2026-34986, affects go-jose v3 and v4 and can cause a panic when a crafted JSON Web Encryption object is decrypted with certain key-wrapping algorithms and an empty encrypted_key field. Red Hat linked that bug to Podman updates for RHEL 10 streams alongside CVE-2026-25679, an IPv6 host literal parsing issue in Go's net/url package, while earlier Podman advisories addressed related Go vulnerabilities such as CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121. The fixes align with upstream go-jose releases 3.0.5 and 4.1.4, which remediate the JWE-triggered denial-of-service condition.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-19, Red Hat published advisory RHSA-2026:19017 for podman on Red Hat Enterprise Linux 10. The Important update released podman 5.8.2-1.el10_2 and fixed CVE-2026-25679 and CVE-2026-34986.
On 2026-05-13, Red Hat published advisory RHSA-2026:17040 for podman on Red Hat Enterprise Linux 10.0 Extended Update Support. The Important update released podman 5.4.0-15.el10_0.1 and fixed multiple Go-related flaws including CVE-2026-34986 and CVE-2026-25679.
On 2026-04-30, Red Hat published advisory RHSA-2026:12028 for podman on Red Hat Enterprise Linux 9.4 Extended Update Support. The Important update released podman 4.9.4-20.el9_4.2 and fixed CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, and CVE-2026-25679.
On 2026-04-24, Red Hat Bugzilla documented CVE-2026-34986 affecting go-jose v3 and v4, where a crafted JWE object can trigger a panic and denial of service. The entry states the issue was fixed upstream in Go JOSE versions 4.1.4 and 3.0.5.
On 2026-04-13, Red Hat published advisory RHSA-2026:7854 for podman on Red Hat Enterprise Linux 9.6 Extended Update Support and related RHEL 9.6 channels. The Important update released podman 5.4.0-20.el9_6.2 and fixed CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121 in bundled Go components.
On 2026-02-25, Red Hat published advisory RHSA-2026:3336 for podman on Red Hat Enterprise Linux 10. The Important update released podman 5.6.0-12.el10_1 and fixed CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121 in bundled Go components.
On 2026-02-25, Red Hat published advisory RHSA-2026:3337 for podman on Red Hat Enterprise Linux 9. The Important update released podman 5.6.0-14.el9_7 and fixed CVE-2025-61729, CVE-2025-61728, CVE-2025-61726, and CVE-2025-68121 in bundled Go components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.