CVE-2026-58015 — glib
MEDIUMCVE-2026-58015 is a medium-severity (CVSS 5.9) Path Traversal vulnerability. A fix is available — see the affected versions and patch details below.
Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-58015.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-58015 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Description
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Affected Products
glibgnomeenterprise linuxredhatDetection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Fix
Upgrade the affected component to the fixed release for CVE-2026-58015, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.
Workarounds
Resolve every user-supplied path to its canonical form and reject anything that escapes the intended directory, and run the component under an account that has no read or write access outside the directory it legitimately serves.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
To exploit this flaw, an attacker must be in a position to perform a man-in-the-middle (MitM) attack on the connection or operate a malicious server that the client connects to. Furthermore, extracting data requires an oracle attack (guessing and hashing), increasing the complexity of exploitation. However, if…
To mitigate this vulnerability, ensure that applications only connect to trusted D-Bus servers and operate within secure, isolated networks to prevent man-in-the-middle (MitM) attacks. If feasible, configuring the D-Bus connection to strictly require the EXTERNAL authentication mechanism and disabling DBUS_COOKIE_SHA1 will completely neutralize this issue.Source: Red Hat security advisory for CVE-2026-58015 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Enterprise Linux 10 | glib2-0:2.80.4-12.el10_2.21 | RHSA-2026:57015 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | glib2-0:2.80.4-4.el10_0.17 | RHSA-2026:65767 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | glib2-0:2.56.1-13.el7_9.1 | RHSA-2026:65773 |
| Red Hat Enterprise Linux 8 | mingw-glib2-0:2.70.1-9.el8_10 | RHSA-2026:49512 |
| Red Hat Enterprise Linux 8 | glib2-0:2.56.4-177.el8_10 | RHSA-2026:61766 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | glib2-0:2.56.4-10.el8_4.7 | RHSA-2026:65762 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | glib2-0:2.56.4-158.el8_6.7 | RHSA-2026:65769 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | glib2-0:2.56.4-165.el8_8.2 | RHSA-2026:65771 |
Frequently Asked Questions
Is CVE-2026-58015 in your dependencies?
Find it across , including transitive dependencies.