Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🛡️
Not in CISA KEV
MEDIUM severity

CVE-2026-58015 — glib

MEDIUM

CVE-2026-58015 is a medium-severity (CVSS 5.9) Path Traversal vulnerability. A fix is available — see the affected versions and patch details below.

Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive

Published
Updated
Affected
2 products
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-58015.

EPSS Exploitation Probability

via FIRST.org ↗
0.8%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs54th percentile — riskier than 54% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-58015 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Description

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

Affected Products

2 products · 6 configurations
Application
glibgnome
< 2.88.1
range
OS
enterprise linuxredhat
5 versions
6.07.08.09.010.0

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for CVE-2026-58015, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Resolve every user-supplied path to its canonical form and reject anything that escapes the intended directory, and run the component under an account that has no read or write access outside the directory it legitimately serves.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate

To exploit this flaw, an attacker must be in a position to perform a man-in-the-middle (MitM) attack on the connection or operate a malicious server that the client connects to. Furthermore, extracting data requires an oracle attack (guessing and hashing), increasing the complexity of exploitation. However, if…

Workaround published by Red Hat
To mitigate this vulnerability, ensure that applications only connect to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle (MitM) attacks. If feasible, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 will completely neutralize this issue.
Source: Red Hat security advisory for CVE-2026-58015 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Enterprise Linux 10glib2-0:2.80.4-12.el10_2.21RHSA-2026:57015
Red Hat Enterprise Linux 10.0 Extended Update Supportglib2-0:2.80.4-4.el10_0.17RHSA-2026:65767
Red Hat Enterprise Linux 7 Extended Lifecycle Supportglib2-0:2.56.1-13.el7_9.1RHSA-2026:65773
Red Hat Enterprise Linux 8mingw-glib2-0:2.70.1-9.el8_10RHSA-2026:49512
Red Hat Enterprise Linux 8glib2-0:2.56.4-177.el8_10RHSA-2026:61766
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportglib2-0:2.56.4-10.el8_4.7RHSA-2026:65762
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportglib2-0:2.56.4-158.el8_6.7RHSA-2026:65769
Red Hat Enterprise Linux 8.8 Telecommunications Update Serviceglib2-0:2.56.4-165.el8_8.2RHSA-2026:65771
UbuntuMEDIUM

Frequently Asked Questions

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
O3 Security · Impact-Aware SCA

Is CVE-2026-58015 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-58015: glib Path Traversal (Medium 5.9)