Podman Project / Podman
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-55686 | Podman: WORKDIR symlink traversal vulnerability | MEDIUM | 5.8 | Jun 26, 2026 |
| CVE-2026-57231 | Podman: Malformed Image can trick podman run into leaking host environment variables into the container | HIGH | 7.5 | Jun 26, 2026 |
| CVE-2026-33414 | PowerShell Command Injection in Podman HyperV Machine | MEDIUM | 4.0 | Apr 14, 2026 |
| CVE-2024-3056 | Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack | HIGH | 8.7 | Aug 2, 2024 |
| CVE-2023-0778 | podman: symlink exchange attack in podman export volume | MEDIUM | 6.8 | Mar 27, 2023 |
| CVE-2022-4123 | podman: Path disclosure | LOW | 3.3 | Dec 8, 2022 |
| CVE-2022-4122 | podman: Symlink error leads to information disclosure | MEDIUM | 5.9 | Dec 8, 2022 |
| CVE-2022-2989 | podman: possible information disclosure and modification | HIGH | 7.1 | Sep 13, 2022 |
| CVE-2022-2739 | podman: Security regression of CVE-2020-14370 due to source code management issue | MEDIUM | 5.3 | Sep 1, 2022 |
| CVE-2022-2738 | podman: Security regression of CVE-2020-8945 due to source code management issue | HIGH | 7.5 | Sep 1, 2022 |
| CVE-2019-25067 | Podman/Varlink API Privilege Escalation | HIGH | 8.8 | Jun 9, 2022 |
| CVE-2022-1227 | psgo: Privilege escalation in 'podman top' | HIGH | 8.7 | Apr 29, 2022 |
| CVE-2022-27649 | podman: Default inheritable capabilities for linux container should be empty | HIGH | 7.5 | Apr 4, 2022 |
| CVE-2021-4024 | podman: podman machine spawns gvproxy with port bound to all IPs | MEDIUM | 6.5 | Dec 23, 2021 |
| CVE-2021-20188 | podman: container users permissions are not respected in privileged containers | HIGH | 7.0 | Feb 11, 2021 |
| CVE-2021-20199 | podman: Remote traffic to rootless containers is seen as orginating from localhost | MEDIUM | 5.9 | Feb 2, 2021 |
| CVE-2020-14370 | podman: environment variables leak between containers when started via Varlink or Docker-compatible REST API | MEDIUM | 5.3 | Sep 23, 2020 |
| CVE-2019-10152 | podman: Improper symlink resolution allows access to host files when executing `podman cp` on running containers | HIGH | 7.2 | Jul 30, 2019 |
Showing 1 to 18 of 18 CVEs