CRI-O
v1.35.7Kubernetes CoreAug 24, 2026
A security maintenance release fixes a vulnerability involving newline handling in the `HOME` environment variable. The fix addresses a bypass that could allow `/etc/passwd` injection.
Action needed (1)
securityhighCVE-2026-15809 newline handling in
HOMEFixes CVE-2026-15809, which allowed
/etc/passwdinjection through newline characters in theHOMEenvironment variable. The check now matches actual newline bytes instead of the literal string"\n".
Add CRI-O to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.