{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32146.json"
      }
    ],
    "title": "gleam: Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.",
    "tracking": {
      "current_release_date": "2026-06-30T04:06:02+00:00",
      "generator": {
        "date": "2026-06-30T04:06:02+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.0"
        }
      },
      "id": "CVE-2026-32146",
      "initial_release_date": "2026-04-11T12:59:22.911000+00:00",
      "revision_history": [
        {
          "date": "2026-04-11T12:59:22.911000+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-05-21T20:20:07+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-06-30T04:06:02+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 10",
                "product": {
                  "name": "Red Hat Enterprise Linux 10",
                  "product_id": "red_hat_enterprise_linux_10",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:10"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 10"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "red_hat_enterprise_linux_7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 7"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 8",
                "product": {
                  "name": "Red Hat Enterprise Linux 8",
                  "product_id": "red_hat_enterprise_linux_8",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 8"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 9",
                "product": {
                  "name": "Red Hat Enterprise Linux 9",
                  "product_id": "red_hat_enterprise_linux_9",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux 9"
          },
          {
            "category": "product_version",
            "name": "firefox.src",
            "product": {
              "name": "firefox.src",
              "product_id": "firefox.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/firefox?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "firefox",
            "product": {
              "name": "firefox",
              "product_id": "firefox",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/firefox"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gjs-devel",
            "product": {
              "name": "gjs-devel",
              "product_id": "gjs-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gjs-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "gjs.src",
            "product": {
              "name": "gjs.src",
              "product_id": "gjs.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/gjs?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "thunderbird",
            "product": {
              "name": "thunderbird",
              "product_id": "thunderbird",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/thunderbird"
              }
            }
          },
          {
            "category": "product_version",
            "name": "thunderbird.src",
            "product": {
              "name": "thunderbird.src",
              "product_id": "thunderbird.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/thunderbird?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mozjs60.src",
            "product": {
              "name": "mozjs60.src",
              "product_id": "mozjs60.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mozjs60?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mozjs60-devel",
            "product": {
              "name": "mozjs60-devel",
              "product_id": "mozjs60-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mozjs60-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mozjs60",
            "product": {
              "name": "mozjs60",
              "product_id": "mozjs60",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mozjs60"
              }
            }
          },
          {
            "category": "product_version",
            "name": "firefox-x11",
            "product": {
              "name": "firefox-x11",
              "product_id": "firefox-x11",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/firefox-x11"
              }
            }
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:firefox"
        },
        "product_reference": "firefox",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox.src as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:firefox.src"
        },
        "product_reference": "firefox.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gjs-devel as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:gjs-devel"
        },
        "product_reference": "gjs-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gjs.src as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:gjs.src"
        },
        "product_reference": "gjs.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:thunderbird"
        },
        "product_reference": "thunderbird",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird.src as a component of Red Hat Enterprise Linux 10",
          "product_id": "red_hat_enterprise_linux_10:thunderbird.src"
        },
        "product_reference": "thunderbird.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox as a component of Red Hat Enterprise Linux 7",
          "product_id": "red_hat_enterprise_linux_7:firefox"
        },
        "product_reference": "firefox",
        "relates_to_product_reference": "red_hat_enterprise_linux_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox.src as a component of Red Hat Enterprise Linux 7",
          "product_id": "red_hat_enterprise_linux_7:firefox.src"
        },
        "product_reference": "firefox.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:firefox"
        },
        "product_reference": "firefox",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:firefox.src"
        },
        "product_reference": "firefox.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mozjs60 as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:mozjs60"
        },
        "product_reference": "mozjs60",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mozjs60-devel as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:mozjs60-devel"
        },
        "product_reference": "mozjs60-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mozjs60.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:mozjs60.src"
        },
        "product_reference": "mozjs60.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:thunderbird"
        },
        "product_reference": "thunderbird",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird.src as a component of Red Hat Enterprise Linux 8",
          "product_id": "red_hat_enterprise_linux_8:thunderbird.src"
        },
        "product_reference": "thunderbird.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:firefox"
        },
        "product_reference": "firefox",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox-x11 as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:firefox-x11"
        },
        "product_reference": "firefox-x11",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "firefox.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:firefox.src"
        },
        "product_reference": "firefox.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gjs-devel as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:gjs-devel"
        },
        "product_reference": "gjs-devel",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gjs.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:gjs.src"
        },
        "product_reference": "gjs.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:thunderbird"
        },
        "product_reference": "thunderbird",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "thunderbird.src as a component of Red Hat Enterprise Linux 9",
          "product_id": "red_hat_enterprise_linux_9:thunderbird.src"
        },
        "product_reference": "thunderbird.src",
        "relates_to_product_reference": "red_hat_enterprise_linux_9"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-32146",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "discovery_date": "2026-04-11T14:00:57.102755+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_enterprise_linux_10:firefox",
            "red_hat_enterprise_linux_10:firefox.src",
            "red_hat_enterprise_linux_10:gjs-devel",
            "red_hat_enterprise_linux_10:gjs.src",
            "red_hat_enterprise_linux_10:thunderbird",
            "red_hat_enterprise_linux_10:thunderbird.src",
            "red_hat_enterprise_linux_7:firefox",
            "red_hat_enterprise_linux_7:firefox.src",
            "red_hat_enterprise_linux_8:firefox",
            "red_hat_enterprise_linux_8:firefox.src",
            "red_hat_enterprise_linux_8:mozjs60",
            "red_hat_enterprise_linux_8:mozjs60-devel",
            "red_hat_enterprise_linux_8:mozjs60.src",
            "red_hat_enterprise_linux_8:thunderbird",
            "red_hat_enterprise_linux_8:thunderbird.src",
            "red_hat_enterprise_linux_9:firefox",
            "red_hat_enterprise_linux_9:firefox-x11",
            "red_hat_enterprise_linux_9:firefox.src",
            "red_hat_enterprise_linux_9:gjs-devel",
            "red_hat_enterprise_linux_9:gjs.src",
            "red_hat_enterprise_linux_9:thunderbird",
            "red_hat_enterprise_linux_9:thunderbird.src"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2457578"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Gleam compiler. A malicious direct or transitive git dependency can exploit an improper path validation vulnerability in the Gleam compiler's handling of git dependencies during dependency download. This allows for arbitrary file system modification, including the deletion and creation of directories outside the intended dependency directory, potentially leading to data loss. In certain environments, this could be further leveraged to achieve arbitrary code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "gleam: Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling.",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "red_hat_enterprise_linux_10:firefox",
          "red_hat_enterprise_linux_10:firefox.src",
          "red_hat_enterprise_linux_10:gjs-devel",
          "red_hat_enterprise_linux_10:gjs.src",
          "red_hat_enterprise_linux_10:thunderbird",
          "red_hat_enterprise_linux_10:thunderbird.src",
          "red_hat_enterprise_linux_7:firefox",
          "red_hat_enterprise_linux_7:firefox.src",
          "red_hat_enterprise_linux_8:firefox",
          "red_hat_enterprise_linux_8:firefox.src",
          "red_hat_enterprise_linux_8:mozjs60",
          "red_hat_enterprise_linux_8:mozjs60-devel",
          "red_hat_enterprise_linux_8:mozjs60.src",
          "red_hat_enterprise_linux_8:thunderbird",
          "red_hat_enterprise_linux_8:thunderbird.src",
          "red_hat_enterprise_linux_9:firefox",
          "red_hat_enterprise_linux_9:firefox-x11",
          "red_hat_enterprise_linux_9:firefox.src",
          "red_hat_enterprise_linux_9:gjs-devel",
          "red_hat_enterprise_linux_9:gjs.src",
          "red_hat_enterprise_linux_9:thunderbird",
          "red_hat_enterprise_linux_9:thunderbird.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-32146"
        },
        {
          "category": "external",
          "summary": "RHBZ#2457578",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457578"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-32146",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-32146"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-32146",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32146"
        },
        {
          "category": "external",
          "summary": "https://cna.erlef.org/cves/CVE-2026-32146.html",
          "url": "https://cna.erlef.org/cves/CVE-2026-32146.html"
        },
        {
          "category": "external",
          "summary": "https://github.com/gleam-lang/gleam/commit/1aa5d8e594b0aa240bb213fce6ee19c65e6d5bcf",
          "url": "https://github.com/gleam-lang/gleam/commit/1aa5d8e594b0aa240bb213fce6ee19c65e6d5bcf"
        },
        {
          "category": "external",
          "summary": "https://github.com/gleam-lang/gleam/commit/55bb36e6d7febfbbc48c4d001e0ae13eb0312d78",
          "url": "https://github.com/gleam-lang/gleam/commit/55bb36e6d7febfbbc48c4d001e0ae13eb0312d78"
        },
        {
          "category": "external",
          "summary": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j",
          "url": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j"
        },
        {
          "category": "external",
          "summary": "https://osv.dev/vulnerability/EEF-CVE-2026-32146",
          "url": "https://osv.dev/vulnerability/EEF-CVE-2026-32146"
        }
      ],
      "release_date": "2026-04-11T12:59:22.911000+00:00",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "red_hat_enterprise_linux_10:firefox",
            "red_hat_enterprise_linux_10:firefox.src",
            "red_hat_enterprise_linux_10:gjs-devel",
            "red_hat_enterprise_linux_10:gjs.src",
            "red_hat_enterprise_linux_10:thunderbird",
            "red_hat_enterprise_linux_10:thunderbird.src",
            "red_hat_enterprise_linux_7:firefox",
            "red_hat_enterprise_linux_7:firefox.src",
            "red_hat_enterprise_linux_8:firefox",
            "red_hat_enterprise_linux_8:firefox.src",
            "red_hat_enterprise_linux_8:mozjs60",
            "red_hat_enterprise_linux_8:mozjs60-devel",
            "red_hat_enterprise_linux_8:mozjs60.src",
            "red_hat_enterprise_linux_8:thunderbird",
            "red_hat_enterprise_linux_8:thunderbird.src",
            "red_hat_enterprise_linux_9:firefox",
            "red_hat_enterprise_linux_9:firefox-x11",
            "red_hat_enterprise_linux_9:firefox.src",
            "red_hat_enterprise_linux_9:gjs-devel",
            "red_hat_enterprise_linux_9:gjs.src",
            "red_hat_enterprise_linux_9:thunderbird",
            "red_hat_enterprise_linux_9:thunderbird.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "red_hat_enterprise_linux_10:firefox",
            "red_hat_enterprise_linux_10:firefox.src",
            "red_hat_enterprise_linux_10:gjs-devel",
            "red_hat_enterprise_linux_10:gjs.src",
            "red_hat_enterprise_linux_10:thunderbird",
            "red_hat_enterprise_linux_10:thunderbird.src",
            "red_hat_enterprise_linux_7:firefox",
            "red_hat_enterprise_linux_7:firefox.src",
            "red_hat_enterprise_linux_8:firefox",
            "red_hat_enterprise_linux_8:firefox.src",
            "red_hat_enterprise_linux_8:mozjs60",
            "red_hat_enterprise_linux_8:mozjs60-devel",
            "red_hat_enterprise_linux_8:mozjs60.src",
            "red_hat_enterprise_linux_8:thunderbird",
            "red_hat_enterprise_linux_8:thunderbird.src",
            "red_hat_enterprise_linux_9:firefox",
            "red_hat_enterprise_linux_9:firefox-x11",
            "red_hat_enterprise_linux_9:firefox.src",
            "red_hat_enterprise_linux_9:gjs-devel",
            "red_hat_enterprise_linux_9:gjs.src",
            "red_hat_enterprise_linux_9:thunderbird",
            "red_hat_enterprise_linux_9:thunderbird.src"
          ]
        }
      ],
      "title": "gleam: Gleam compiler: Arbitrary file system modification and potential code execution via improper path validation in git dependency handling."
    }
  ]
}