{"id":"DEBIAN-CVE-2026-107935","details":"A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.","modified":"2026-10-10T05:00:07.679028816Z","published":"2026-10-09T10:16:37.497Z","upstream":["CVE-2026-107935"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-107935"}],"affected":[{"package":{"name":"golang-github-containers-gvisor-tap-vsocks","ecosystem":"Debian:13","purl":"pkg:deb/debian/golang-github-containers-gvisor-tap-vsocks?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.1-3","0.8.1-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-107935.json"}},{"package":{"name":"golang-github-containers-gvisor-tap-vsocks","ecosystem":"Debian:14","purl":"pkg:deb/debian/golang-github-containers-gvisor-tap-vsocks?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.8.1-3","0.8.1-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-107935.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H"}]}