Home/Product/flatpak
Product

flatpak

18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-40354
< 1.20.4
Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via
2.9LOW
CVE-2026-39977
>= 1.4.5 and < 1.4.8
flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array
6.3MEDIUM
CVE-2026-34079
< 1.16.4
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cach
7.5HIGH
CVE-2026-34078
<= 1.16.3
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the san
10.0CRITICAL
CVE-2026-34080
< 0.1.7
xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassing eavesdro
5.5MEDIUM
CVE-2024-42472
>= 1.14.0 and < 1.14.10
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or comprom
10.0CRITICAL
CVE-2024-32462
< 1.10.9
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.
8.4HIGH
CVE-2023-28101
< 1.10.8
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.8,
5.0MEDIUM
CVE-2023-28100
< 1.10.8
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Versions prior to 1.10.8, 1.1
10.0CRITICAL
CVE-2022-21682
< 1.2.2
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak p
7.7HIGH
CVE-2021-43860
< 1.10.6
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properl
8.2HIGH
CVE-2021-41133
< 1.8.2
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 a
8.8HIGH
CVE-2021-21381
>= 0.9.4 and < 1.10.2
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9
7.1HIGH
CVE-2021-21261
>= 0.11.4 and < 1.8.5
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `
7.3HIGH
CVE-2019-10063
< 1.0.8
Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 a
9.0CRITICAL
CVE-2019-8308
< 1.0.7
Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to
8.2HIGH
CVE-2018-6560
< 0.8.9
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can
8.8HIGH
CVE-2017-9780
<= 0.8.6
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissio
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin