Skip to main content
Vulnerability Database/CVE-2026-90959

CVE-2026-90959: Pulpcore Path Traversal Vulnerability

CVE-2026-90959 is a path traversal vulnerability in pulpcore that allows authenticated users to read sensitive files through URL manipulation. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-90959 Overview

A path traversal vulnerability [CWE-22] exists in pulpcore's content upload API. The API accepts a file_url parameter so users with file repository privileges can specify a local file URL for Pulp to download and store. The scheme validation rejects URLs beginning with file://, but Python's URL parser also recognizes the file: scheme without double slashes. This mismatch between validated input and dispatched input lets an authenticated low-privilege user supply crafted URLs with relative path traversal sequences. The attacker can then read any file accessible to the Pulp server process.

Critical Impact

In deployments running Pulp Container, an attacker can read the container registry token signing private key and forge bearer tokens, granting unauthorized access to all private container repositories.

Affected Products

  • Pulpcore (content upload API)
  • Pulp Container (impact amplified via token signing key disclosure)
  • Red Hat distributions bundling pulpcore

Discovery Timeline

  • 2026-09-24 - CVE CVE-2026-90959 published to NVD
  • 2026-10-01 - Last updated in NVD database

Technical Details for CVE-2026-90959

Vulnerability Analysis

The flaw originates in how pulpcore validates URL schemes submitted through the file_url parameter of the content upload API. Validation relies on a string prefix comparison that only rejects values beginning with file://. Python's URL parser, however, treats file: without the double slashes as a valid file scheme and routes the request to the file downloader. The validator and the downstream dispatcher disagree on what constitutes a local file URL.

An authenticated user with file repository privileges can send a value such as file:../../etc/passwd or similar relative traversal payloads. The scheme check passes because the string does not start with file://, yet the downloader resolves the request against the local filesystem. Pulp then reads the targeted file and stores its contents as uploaded content accessible to the attacker.

The maximum impact appears in deployments that include Pulp Container. The container registry token signing private key resides on disk and is readable by the Pulp process. An attacker who exfiltrates this key can mint arbitrary bearer tokens and pull any private image from the registry.

Root Cause

The root cause is inconsistent URL scheme handling. A naive startswith("file://") check is not equivalent to RFC-compliant scheme parsing. Any file: URI lacking the authority component bypasses the deny list while remaining a valid file scheme to urllib.

Attack Vector

Exploitation requires authenticated access with file repository permissions over the network. The attacker submits a crafted file_url to the content upload API containing the file: prefix and relative path traversal sequences. Pulp downloads the referenced local file and stores it as retrievable content. See the Red Hat CVE-2026-90959 Advisory for additional technical context.

Detection Methods for CVE-2026-90959

Indicators of Compromise

  • Content upload API requests containing a file_url parameter with the file: scheme, especially variants lacking double slashes.
  • Upload requests whose file_url values contain .., %2e%2e, or other relative traversal sequences.
  • Newly uploaded artifacts whose content matches sensitive host paths such as /etc/passwd, SSH keys, or the container registry token signing key.
  • Unexpected issuance of container registry bearer tokens or anomalous pulls of private images.

Detection Strategies

  • Inspect pulpcore API access logs for POST requests to the content upload endpoint referencing file: URIs.
  • Correlate low-privilege user accounts with uploads that produce artifacts matching known filesystem paths on the Pulp host.
  • Alert on reads of the Pulp Container token signing private key by the Pulp service account outside normal signing workflows.

Monitoring Recommendations

  • Enable verbose audit logging on the pulpcore content upload API and forward events to a central SIEM.
  • Monitor filesystem access to credential and key material owned by the Pulp service user.
  • Track container registry authentication events for tokens issued without a corresponding login flow.

How to Mitigate CVE-2026-90959

Immediate Actions Required

  • Apply the pulpcore security update referenced in the Red Hat CVE-2026-90959 Advisory as soon as it is available for your distribution.
  • Rotate the Pulp Container registry token signing private key and invalidate previously issued bearer tokens if exposure is suspected.
  • Audit recent uploads for artifacts containing host filesystem contents and remove compromised objects.
  • Review and tighten assignment of file repository privileges to limit the pool of users who can call the vulnerable API.

Patch Information

Refer to the Red Hat CVE-2026-90959 Advisory and Red Hat Bug Report #2533037 for fixed package versions and backport details. The fix replaces the prefix comparison with proper URL parsing so any file: scheme is rejected regardless of authority formatting.

Workarounds

  • Restrict the content upload API to trusted administrators until patched versions are deployed.
  • Place a reverse proxy or WAF rule in front of pulpcore that rejects requests whose file_url parameter contains the file: scheme or traversal sequences such as ...
  • Run the Pulp service under a dedicated low-privilege account with filesystem permissions scoped to repository storage paths, excluding registry signing keys where feasible.
bash
# Example reverse proxy filter (nginx) blocking file: scheme in file_url
if ($arg_file_url ~* "^file:") {
    return 400;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.