CVE-2026-84232 Overview
CVE-2026-84232 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in pulpcore's content serving application. Pulp serves files uploaded to file-type repositories using their original content type and omits the Content-Disposition: attachment header when local filesystem storage is configured. An authenticated user with content upload permissions can upload a crafted HTML or SVG file containing JavaScript. That payload executes in the browser of any user who later visits the file URL, running in the security context of the host application.
Critical Impact
Authenticated attackers with upload permissions can achieve stored XSS in the host application context, enabling session theft, credential harvesting, and actions on behalf of victim users.
Affected Products
- Pulpcore content serving application
- Pulp file-type repositories using local filesystem storage
- Red Hat products bundling affected pulpcore versions
Discovery Timeline
- 2026-09-01 - CVE-2026-84232 published to NVD
- 2026-09-01 - Last updated in NVD database
Technical Details for CVE-2026-84232
Vulnerability Analysis
The flaw exists in how pulpcore delivers files stored in file-type repositories. When a client requests an uploaded file, the content server returns the file using its inferred original MIME type. HTML files return with text/html, and SVG files return with image/svg+xml. Both formats support inline scripting through <script> tags and event handler attributes.
The server also omits the Content-Disposition: attachment response header. Without this header, browsers render the response inline rather than prompting a download. The combination causes the browser to parse and execute embedded JavaScript from attacker-controlled content within the origin of the Pulp application.
Because execution occurs in the origin of the host application, injected scripts can read authenticated session cookies not marked HttpOnly, issue authenticated API calls, and modify the DOM presented to other users. Successful exploitation requires an authenticated actor with upload permissions and a victim who clicks or is redirected to the crafted file URL.
Root Cause
The root cause is missing output sanitization at the content delivery layer. Pulpcore trusts the file extension and MIME type of uploaded artifacts and passes them through to responses without forcing a safe content type or attachment disposition for renderable formats.
Attack Vector
An attacker with content upload permissions uploads an .html or .svg file containing JavaScript into a Pulp file repository. The attacker then distributes the resulting file URL to a target user through phishing, chat, or embedded links. When the victim opens the URL in an authenticated browser session, the injected script executes under the Pulp origin and can perform any action the victim's session permits.
No verified public proof-of-concept code is available. See the Red Hat CVE-2026-84232 advisory and Red Hat Bug Report #2526807 for vendor technical details.
Detection Methods for CVE-2026-84232
Indicators of Compromise
- Uploaded artifacts in file repositories with extensions .html, .htm, .svg, or .xhtml originating from non-administrative accounts.
- HTTP responses from Pulp content endpoints returning Content-Type: text/html or image/svg+xml without Content-Disposition: attachment.
- Unexpected outbound requests from user browsers to attacker-controlled domains immediately after visits to Pulp content URLs.
Detection Strategies
- Inspect stored files in Pulp file repositories for <script>, onerror, onload, and javascript: patterns using content scanning.
- Review web access logs for GET requests to content URLs ending in renderable extensions and correlate with upload events by the same user or repository.
- Alert on authenticated Pulp API calls that occur immediately after a user retrieves a file with an HTML or SVG content type.
Monitoring Recommendations
- Enable audit logging for all upload operations to Pulp file repositories and forward logs to a centralized analytics platform.
- Track anomalous behavior from accounts holding content upload permissions, including bulk uploads of renderable file types.
- Monitor browser-side telemetry for Content Security Policy (CSP) violations triggered by Pulp origins.
How to Mitigate CVE-2026-84232
Immediate Actions Required
- Apply the pulpcore security update referenced in the Red Hat CVE-2026-84232 advisory as soon as a fixed version is available for your distribution.
- Audit accounts with content upload permissions and revoke access from users that do not require it.
- Review existing file repositories for previously uploaded .html, .htm, and .svg files and quarantine any that are not required for legitimate operations.
Patch Information
Refer to the vendor advisory at Red Hat CVE-2026-84232 and Red Hat Bug Report #2526807 for fixed package versions and product-specific errata.
Workarounds
- Place a reverse proxy in front of the Pulp content server that rewrites responses for renderable file types to set Content-Type: application/octet-stream and add Content-Disposition: attachment.
- Serve Pulp content from a separate sandbox domain that shares no cookies or authenticated session state with the primary Pulp application.
- Deploy a strict Content Security Policy on the Pulp origin that disables inline script execution and restricts script sources.
- Restrict upload permissions to trusted service accounts until the patched pulpcore version is deployed.
# Example nginx reverse proxy snippet to force attachment disposition for Pulp content
location /pulp/content/ {
proxy_pass http://pulp_upstream;
proxy_hide_header Content-Disposition;
add_header Content-Disposition "attachment" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Content-Security-Policy "default-src 'none'; sandbox" always;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.