A flaw was found in Podman. The podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry. This issue results in a Man In The Middle attack.
https://access.redhat.com/errata/RHSA-2025:9766
https://access.redhat.com/errata/RHSA-2025:9751
https://access.redhat.com/errata/RHSA-2025:9726
https://access.redhat.com/errata/RHSA-2025:15397
https://access.redhat.com/errata/RHSA-2025:11681
https://access.redhat.com/errata/RHSA-2025:11677
https://access.redhat.com/errata/RHSA-2025:11363
https://access.redhat.com/errata/RHSA-2025:11359
https://access.redhat.com/errata/RHSA-2025:10668
https://access.redhat.com/errata/RHSA-2025:10551
https://access.redhat.com/errata/RHSA-2025:10550
Published: 2025-06-24
Updated: 2026-08-31
Named Vulnerability: GO-2025-3777Named Vulnerability: GHSA-65gg-3w2w-hr4h
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.3
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity: High
EPSS: 0.00019