Flatpak is a containerization framework for distributing Linux applications that has gained prominence in the desktop and server application-delivery landscape. Vulnerabilities affecting the vendor and its associated tools—including the core Flatpak runtime, Flatpak Builder, and the XDG Desktop Portal and D-Bus proxy components—skew toward serious outcomes and recur through a consistent pattern of input-validation, path-traversal, and injection-class flaws that reflect the sandbox-enforcement and inter-process communication layers these tools occupy. Defenders deploying Flatpak in security-sensitive contexts should prioritize advisories around sandboxing bypass and privilege-escalation vectors; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flatpak over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34078CRITICAL Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled sy | Apr 7, 2026 | 10.0 | 39 | NO | NO |
CVE-2024-42472CRITICAL Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories coul | Aug 15, 2024 | 10.0 | 31 | NO | NO |
CVE-2021-43860HIGH Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the u | Jan 12, 2022 | 8.6 | 28 | NO | NO |
CVE-2019-10063CRITICAL Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions since 0.8.1 address CVE-2017-5226 by using a seccomp filter to | Mar 26, 2019 | 9.0 | 28 | NO | NO |
CVE-2024-32462HIGH Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromis | Apr 18, 2024 | 8.4 | 27 | NO | NO |
CVE-2018-6560HIGH In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because white | Feb 2, 2018 | 8.8 | 27 | NO | NO |
CVE-2026-34079HIGH Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app con | Apr 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2021-21261HIGH Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` service that can allow sandboxed a | Jan 14, 2021 | 8.8 | 26 | NO | NO |
CVE-2017-9780HIGH In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The file | Jun 21, 2017 | 7.8 | 25 | NO | NO |
CVE-2022-21682MEDIUM Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies | Jan 13, 2022 | 6.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flatpak.
Media articles that mention a CVE ID that affects a product developed by Flatpak — matched by CVE ID, not by vendor name.