Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 23 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat hardened Images
Redhat openshift Container Platform |
|
| Vendors & Products |
Redhat hardened Images
Redhat openshift Container Platform |
Thu, 28 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 28 May 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction. | |
| Title | Rpm: command injection in rpmuncompress dountar() via unescaped archive top-level directory name in popen() shell command | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat pdrive Lightspeed Redhat quarkus Redhat satellite |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:openshift:4 cpe:/a:redhat:pdrive_lightspeed:0 cpe:/a:redhat:quarkus:3 cpe:/a:redhat:satellite:6 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird Redhat openshift Redhat pdrive Lightspeed Redhat quarkus Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-25T23:07:18.618Z
Reserved: 2026-05-07T03:57:03.811Z
Link: CVE-2026-44604
Updated: 2026-05-28T12:15:20.380Z
Status : Awaiting Analysis
Published: 2026-05-28T08:16:35.280
Modified: 2026-06-17T10:51:09.140
Link: CVE-2026-44604
OpenCVE Enrichment
Updated: 2026-05-30T21:19:20Z