Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-45774

CVE-2026-45774: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.4

    High [CVE-2026-45774] Arbitrary file read via path traversal in profile import

    CVE-2026-45774Source published Source updated

    compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them with `trestle_root` and calling `.resolve()`, but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with `imports[].href` containing path traversal sequences to read arbitrary files from the server filesystem. Successful exploitation could enable the attacker to read arbitrary files from the server's filesystem, potentially leading to sensitive information disclosure. This Important vulnerability in `compliance-trestle`, utilized by the File Integrity Operator…

    Affected products in this advisory
    • File Integrity Operator
    Source-reported affected versions
    • < 3.12.2
    • < 4.0.3
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • To mitigate this issue, ensure that only trusted OSCAL profile YAML files are imported and processed by systems utilizing `compliance-trestle`. Avoid importing or processing OSCAL profile YAML files from untrusted or unverified sources.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery