Flatpak-builder is a tool for building flatpaks from sources.
See https://flatpak.org/ for more information.
Update Information:
This update includes a fix for CVE-2026-39977. See also: the upstream advisory
* Tue Apr 14 2026 Adrian Vovk
[ 1 ] Bug #2457166 - flatpak-builder-1.4.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2457166
[ 2 ] Bug #2457894 - CVE-2026-39977 flatpak-builder: path traversal leading to arbitrary file read on host when installing licence files [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2457894
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-631b9d535c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.