CVE-2026-103870

CVE-2026-103870 published: A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and wri...

View full NVD advisory → ← Back to CVE watch