CVE-2026-56876
CVE-2026-56876: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh8.1
High [CVE-2026-56876] Arbitrary file write and information disclosure via symlink validation bypass
CVE-2026-56876Source published Source updated
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files. This vulnerability allows a remote attacker to craft a malicious zip file containing symbolic links that point to locations outside the intended extraction directory. This could enable an attacker to read or write to sensitive files, potentially leading to information disclosure or system compromise. A flaw was found in the extract-zip npm package. Exploitation requires a user or automated process to…
- Affected products in this advisory
- Red Hat Enterprise Linux 10
- Node HealthCheck Operator
- Red Hat package: rh-podman-desktop
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- rh-podman-desktop-0:1.1.2-1.el10_2
- RHSA-2026:57590
- Mitigation guidance
- No patch is available for extract-zip. The upstream maintainer is unresponsive (last commit 4+ years ago), and no fix is expected. Users should avoid using this package to extract untrusted ZIP archives. As a workaround, validate symlink targets manually before extraction, use an alternative library such as adm-zip or yauzl with proper path validation, or run extraction in a sandboxed environment (container, isolated filesystem).
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.