{"schema_version":"1.7.3","id":"GHSA-65gg-3w2w-hr4h","published":"2025-06-25T21:57:00Z","modified":"2026-02-04T04:19:14.028511Z","aliases":["CVE-2025-6032","GO-2025-3777"],"related":["CGA-68hh-wjg4-3v49"],"summary":"Podman Improper Certificate Validation; machine missing TLS verification","details":"### Impact\nThe podman machine init command fails to verify the TLS certificate when downloading the VM images from an OCI registry (which it does by default since 5.0.0) allowing a possible Man In The Middle attack.\n\n### Patches\nhttps://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3\nFixed in v5.5.2\n\n### Workarounds\nDownload the disk image manually via some other tool that verifies the TLS connection. Then pass the local image as file path (podman machine init --image ./somepath)","affected":[{"package":{"name":"github.com/containers/podman/v4","ecosystem":"Go","purl":"pkg:golang/github.com/containers/podman/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.8.0"},{"last_affected":"4.9.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-65gg-3w2w-hr4h/GHSA-65gg-3w2w-hr4h.json"}},{"package":{"name":"github.com/containers/podman/v5","ecosystem":"Go","purl":"pkg:golang/github.com/containers/podman/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-65gg-3w2w-hr4h/GHSA-65gg-3w2w-hr4h.json"}}],"references":[{"type":"WEB","url":"https://github.com/containers/podman/security/advisories/GHSA-65gg-3w2w-hr4h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6032"},{"type":"WEB","url":"https://github.com/containers/podman/commit/726b506acc8a00d99f1a3a1357ecf619a1f798c3"},{"type":"PACKAGE","url":"https://github.com/containers/podman"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2372501"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2025-6032"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:9766"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:9751"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:9726"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:15397"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:11681"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:11677"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:11363"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:11359"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:10668"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:10551"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:10550"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:10549"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:10295"}],"database_specific":{"cwe_ids":["CWE-295"],"github_reviewed":true,"github_reviewed_at":"2025-06-25T21:57:00Z","nvd_published_at":"2025-06-24T14:15:30Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}