{"id":"AZL-100908","summary":"CVE-2026-87766 affecting package bubblewrap 0.8.0-1","details":"A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.","modified":"2026-09-16T06:39:01Z","published":"2026-09-09T09:17:12Z","upstream":["CVE-2026-87766"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87766"}],"affected":[{"package":{"name":"bubblewrap","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/bubblewrap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.8.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100908.json"}}],"schema_version":"1.9.0"}