GLib D-Bus DBUS_COOKIE_SHA1 Auth: CookieCtx Path Traversal CVE-2026-58015
CVE-2026-58015 Published on June 30, 2026
Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.
Vulnerability Analysis
CVE-2026-58015 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-58015 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-58015
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
GNOME GLib:- Before 2.88.1 is affected.
- Version 0:2.80.4-12.el10_2.21 and below * is unaffected.
- Version 0:2.80.4-4.el10_0.17 and below * is unaffected.
- Version 0:2.56.1-13.el7_9.1 and below * is unaffected.
- Version 0:2.70.1-9.el8_10 and below * is unaffected.
- Version 0:2.56.4-177.el8_10 and below * is unaffected.
- Version 0:2.56.4-10.el8_4.7 and below * is unaffected.
- Version 0:2.56.4-10.el8_4.7 and below * is unaffected.
- Version 0:2.56.4-158.el8_6.7 and below * is unaffected.
- Version 0:2.56.4-158.el8_6.7 and below * is unaffected.
- Version 0:2.56.4-165.el8_8.2 and below * is unaffected.
- Version 0:2.56.4-165.el8_8.2 and below * is unaffected.
- Version 0:2.68.4-19.el9_8.9 and below * is unaffected.
- Version 0:2.68.4-19.el9_8.9 and below * is unaffected.
- Version 0:2.68.4-7.el9_2.7 and below * is unaffected.
- Version 0:2.68.4-14.el9_4.8 and below * is unaffected.
- Version 0:2.68.4-16.el9_6.7 and below * is unaffected.
- Version 1788348522 and below * is unaffected.
- Version 1788348571 and below * is unaffected.
- Version 1788348571 and below * is unaffected.
- Version 1788348594 and below * is unaffected.
- Version 1788205779 and below * is unaffected.
- Version 1788206196 and below * is unaffected.
- Version 1787241211 and below * is unaffected.
- Version 1787135742 and below * is unaffected.
- Version 1787241260 and below * is unaffected.
- Version 1788880445 and below * is unaffected.
- Version 1788880464 and below * is unaffected.
- Version 1788880456 and below * is unaffected.
- Version 1788765051 and below * is unaffected.
- Version 1788880581 and below * is unaffected.