Containerd
This hub aggregates every CVE we track for Containerd, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
2
Critical
7
High
0
In CISA KEV
Severity distribution
MEDIUM15HIGH7CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
1
0
2
0
0
0
0
0
2
0
0
1
0
0
0
0
6
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Containerd.
- CVE-2026-53489containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore6.5
- CVE-2026-53492containerd CRI checkpoint restore CDI annotation smuggling9.6
- CVE-2026-50195containerd: CRI checkpoint import allows local image tag poisoning9.9
- CVE-2026-47262containerd image-triggered runtime DoS via unbounded group parsing5.5
- CVE-2026-46680containerd user ID handling bypass allows runAsNonRoot evasion7.8
- CVE-2026-53488containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull8.8
- CVE-2025-47911Quadratic parsing complexity in golang.org/x/net/html5.3
- CVE-2025-64329containerd CRI server: Host memory exhaustion through Attach goroutine leak5.5
- CVE-2024-25621containerd affected by a local privilege escalation via wide permissions on CRI directory7.3
- CVE-2025-47291containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.7.5
- CVE-2025-47290Containerd vulnerable to host filesystem access during image unpack5.9
- CVE-2024-40635containerd has an integer overflow in User ID handling4.6
- CVE-2023-25173containerd supplementary groups are not set up properly5.3
- CVE-2023-25153containerd OCI image importer memory exhaustion6.2
- CVE-2022-23471containerd CRI stream server: Host memory exhaustion through terminal resize goroutine leak5.7
Product normalization is registry-driven with AI assist and human review. How it works