Improper Certificate Validation Affecting github.com/containers/podman/pkg/machine/ocipull package, versions >=4.8.0 <5.5.2


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.03% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCONTAINERSPODMANPKGMACHINEOCIPULL-10500772
  • published26 Jun 2025
  • disclosed25 Jun 2025
  • creditPaul Holzinger

Introduced: 25 Jun 2025

NewCVE-2025-6032  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade github.com/containers/podman/pkg/machine/ocipull to version 5.5.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation via the machine init process. An attacker can intercept or manipulate data in transit by performing a man-in-the-middle attack during the download of VM images from an OCI registry.

Workaround

This vulnerability can be mitigated by manually downloading the disk image using a tool that verifies the TLS connection and then providing the local image file path to the initialization process.

CVSS Base Scores

version 4.0
version 3.1