CVE Browser

Page 1 (more results available)

Vendor: Containerd Remove filter Clear all
CVE-2026-107446 MEDIUM

containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an…

CVSS 6.8 EPSS n/a Oct 8, 2026
CVE-2026-53493 MEDIUM

Containerd has image-pull DoS via crafted OCI index graph amplification

CVSS 6.9 EPSS 0.36% Sep 25, 2026
Go
CVE-2026-53495 MEDIUM

containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service

CVSS 6.8 EPSS 0.16% Sep 14, 2026
Go
CVE-2026-53489 HIGH

containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore

CVSS 8.2 EPSS 0.17% Jul 1, 2026
Go
CVE-2026-53492 HIGH

containerd CRI checkpoint restore CDI annotation smuggling

CVSS 8.4 EPSS 0.35% Jul 1, 2026
Go
CVE-2026-50195 MEDIUM

containerd: CRI checkpoint import allows local image tag poisoning

CVSS 5.6 EPSS 0.30% Jul 1, 2026
Go
CVE-2026-47262 MEDIUM

containerd image-triggered runtime DoS via unbounded group parsing

CVSS 6.9 EPSS 0.27% Jul 1, 2026
Go
CVE-2026-46680 HIGH

containerd user ID handling bypass allows runAsNonRoot evasion

CVSS 7.3 EPSS 0.16% Jul 1, 2026
Go
CVE-2026-53488 CRITICAL

containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull

CVSS 9.4 EPSS 0.16% Jul 1, 2026
Go
CVE-2025-64329 MEDIUM

containerd CRI server: Host memory exhaustion through Attach goroutine leak

CVSS 6.9 EPSS 0.16% Nov 7, 2025
Go
CVE-2024-25621 HIGH

containerd affected by a local privilege escalation via wide permissions on CRI directory

CVSS 7.8 EPSS 0.17% Nov 6, 2025
Go
CVE-2025-47291 MEDIUM

containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.

CVSS 4.6 EPSS 0.28% May 21, 2025
Go
CVE-2025-47290 HIGH

Containerd vulnerable to host filesystem access during image unpack

CVSS 7.6 EPSS 0.50% May 20, 2025
Go
CVE-2024-40635 HIGH

containerd has an integer overflow in User ID handling

CVSS 7.8 EPSS 0.29% Mar 17, 2025
Go
CVE-2023-25173 HIGH

containerd supplementary groups are not set up properly

CVSS 7.8 EPSS 0.54% Feb 16, 2023
Go
CVE-2023-25153 MEDIUM

containerd OCI image importer memory exhaustion

CVSS 6.2 EPSS 0.36% Feb 16, 2023
Go
CVE-2022-23471 MEDIUM

containerd CRI stream server: Host memory exhaustion through terminal resize goroutine leak

CVSS 6.5 EPSS 1.11% Dec 7, 2022
Go
CVE-2022-31030 MEDIUM

containerd CRI plugin: Host memory exhaustion through ExecSync

CVSS 5.5 EPSS 0.38% Jun 6, 2022
Go
CVE-2022-24778 HIGH

Incorrect Authorization in imgcrypt

CVSS 7.5 EPSS 2.72% Mar 25, 2022
Go
CVE-2022-23648 HIGH

Insecure handling of image volumes in containerd CRI plugin

CVSS 7.5 EPSS 27.39% Mar 3, 2022
Go
CVE-2021-43816 CRITICAL

Improper Preservation of Permissions in containerd

CVSS 9.1 EPSS 1.68% Jan 5, 2022
Go
CVE-2021-41103 HIGH

Insufficiently restricted permissions on plugin directories

CVSS 7.8 EPSS 0.52% Oct 4, 2021
Go
CVE-2021-32760 MEDIUM

Archive package allows chmod of file outside of unpack target directory

CVSS 6.3 EPSS 1.59% Jul 19, 2021
Go
CVE-2021-21334 MEDIUM

environment variable leak

CVSS 6.3 EPSS 2.03% Mar 10, 2021
Go
CVE-2020-15257 HIGH

containerd-shim API Exposed to Host Network Containers

CVSS 8.8 EPSS 3.24% Dec 1, 2020
Go

Showing 1 to 25 CVEs · page 1 (more available)