← Downloads

Flatpak 1.18.4

Package v1.18.4 x86_64 TAR.XZ September 28, 2026

Flatpak 1.18.4 is a security release fixing six vulnerabilities, including arbitrary file overwrite and deletion during app installation, an OCI token leak, and a sandbox signal escape.

Download TAR.XZ Project website ↗

Download Mirrors

Mirror Region Download
GitHub Release 1.18.4 (Official) Primary Global Download
GitHub Releases Global Download
Flathub Setup Global Download

Flatpak 1.18.4 was released on September 28, 2026 as a security update, six days after 1.18.3 and a month after 1.18.1. We covered it in the news.

Security fixes

CVEIssue
CVE-2026-97024A malicious app could overwrite arbitrary files with an empty file or symlink during installation
CVE-2026-97023A malicious app could delete arbitrary files with elevated privileges
CVE-2026-97025OCI repository authentication tokens could be read by other local users
CVE-2026-97026Loose permissions on /var/tmp/flatpak-cache-*
CVE-2026-97027Crafted .desktop and D-Bus .service files could cause denial of service
CVE-2026-97029A sandboxed app could signal a process group outside its sandbox

The bundled xdg-dbus-proxy fallback also moves to 0.1.9, fixing CVE-2026-93676 and CVE-2026-94422.

Installing the update

You should get this from your distribution, not from source:

flatpak --version
sudo apt update && sudo apt upgrade flatpak   # Debian / Ubuntu
sudo dnf upgrade flatpak                      # Fedora
sudo pacman -Syu                              # Arch

Distributions sometimes backport security fixes without changing the version number. If your version looks older, check your distro’s security tracker for the CVE IDs above.

Also review which remotes you trust, since every remote can ship code through Flatpak’s privileged install path:

flatpak remotes

Our Flatpak permissions guide covers the sandbox side.

Verify Your Download

Release tarballs on the GitHub release page are accompanied by checksums, and tags are signed by the maintainers.