NVD HIGH: CVE-2026-90959 — A path traversal vulnerability was found in pulpcore. The content upload API acc...
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl
CVE-2026-90959