Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

containerd — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in containerd, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security weaknesses associated with the containerd software product. It serves as a centralized resource for tracking vulnerabilities within this specific container runtime environment, offering visibility into the security posture of the software over time. The collection covers a wide spectrum of vulnerability types, including but not limited to remote code execution, privilege escalation, denial of service, and information disclosure issues. These entries span historical records dating back to the early adoption phases of containerd, ensuring a complete view of past security incidents and patch cycles. Users can utilize this data to track vendor advisories issued by the containerd maintainers and the Cloud Native Computing Foundation. By examining these records, stakeholders can gain a deeper understanding of common weakness classes prevalent in container runtimes and analyze how specific threat vectors have evolved. This resource also allows for the lookup of a product’s vulnerability history, enabling security teams to assess the long-term stability and responsiveness of the containerd project to emerging threats. The aggregated information supports risk assessment activities and helps organizations make informed decisions regarding their container infrastructure security strategies.

Vendor: containerd

CVE ID Title CVSS Severity Published
CVE-2026-53489 containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore CWE-61 - - 2026-07-01
CVE-2026-53492 containerd CRI checkpoint restore CDI annotation smuggling CWE-20 - - 2026-07-01
CVE-2026-50195 containerd: CRI checkpoint import allows local image tag poisoning CWE-345 - - 2026-07-01
CVE-2026-47262 containerd image-triggered runtime DoS via unbounded group parsing CWE-400 - - 2026-07-01
CVE-2026-46680 containerd user ID handling bypass allows runAsNonRoot evasion CWE-269 - - 2026-07-01
CVE-2026-53488 containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull CWE-20 - - 2026-07-01
CVE-2025-64329 containerd CRI server: Host memory exhaustion through Attach goroutine leak CWE-401 7.7 - 2025-11-07
CVE-2024-25621 containerd affected by a local privilege escalation via wide permissions on CRI directory CWE-279 7.3 High 2025-11-06
CVE-2025-47291 containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. CWE-266 7.7AI High AI 2025-05-21
CVE-2025-47290 Containerd vulnerable to host filesystem access during image unpack CWE-367 6.3AI Medium AI 2025-05-20
CVE-2024-40635 containerd has an integer overflow in User ID handling CWE-190 4.6 Medium 2025-03-17
CVE-2023-25173 containerd supplementary groups are not set up properly CWE-863 5.3 Medium 2023-02-16
CVE-2023-25153 containerd OCI image importer memory exhaustion CWE-770 6.2 Medium 2023-02-16
CVE-2022-23471 containerd CRI stream server: Host memory exhaustion through terminal resize goroutine leak CWE-400 5.7 Medium 2022-12-07
CVE-2022-31030 containerd CRI plugin: Host memory exhaustion through ExecSync CWE-400 5.5 Medium 2022-06-06
CVE-2022-23648 Insecure handling of image volumes in containerd CRI plugin CWE-200 7.5 High 2022-03-03
CVE-2021-43816 Improper Preservation of Permissions in containerd CWE-281 8.0 High 2022-01-05
CVE-2021-41103 Insufficiently restricted permissions on plugin directories CWE-22 7.8 - 2021-10-04
CVE-2021-32760 Archive package allows chmod of file outside of unpack target directory CWE-668 5.0 Medium 2021-07-19
CVE-2021-21334 environment variable leak CWE-668 6.3 Medium 2021-03-10
CVE-2020-15257 containerd-shim API Exposed to Host Network Containers CWE-669 5.2 Medium 2020-12-01
CVE-2020-15157 containerd can be coerced into leaking credentials during image pull CWE-522 6.1 Medium 2020-10-16

All 22 known CVE vulnerabilities affecting containerd with full Chinese analysis, references, and POCs where available.