Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

containerd — Vulnerabilities & Security Advisories 26

Browse all 26 CVE security advisories affecting containerd. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Containerd serves as an industry-standard container runtime for managing container lifecycle, widely adopted in Kubernetes environments. Historically, vulnerabilities have included remote code execution, privilege escalation, and denial-of-service flaws, often stemming from improper input validation or insecure default configurations. The project maintains a security-first approach with regular audits and a vulnerability disclosure program. While no major incidents have been widely reported, the 17 documented CVEs highlight potential risks in areas like image handling and runtime process isolation. Organizations should implement strict access controls and keep components updated to mitigate risks, as containerd's position in critical infrastructure makes it a potential target for attacks seeking to compromise containerized environments.

Top products by containerd: containerd imgcrypt overlaybd
CVE ID Title CVSS Severity Published
CVE-2026-107446 containerd ≤1.0.18 overlaybd整数溢出漏洞 — overlaybd CWE-190 6.8 Medium 2026-10-08
CVE-2026-53493 Containerd has image-pull DoS via crafted OCI index graph amplification — containerd CWE-400 6.9 Medium 2026-09-25
CVE-2026-53495 containerd CRI ExecSync Goroutine Leak Leading to Node-Level Denial of Service — containerd CWE-400 6.8 Medium 2026-09-14
CVE-2026-53489 containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore — containerd CWE-61 - - 2026-07-01
CVE-2026-53492 containerd CRI checkpoint restore CDI annotation smuggling — containerd CWE-20 - - 2026-07-01
CVE-2026-50195 containerd: CRI checkpoint import allows local image tag poisoning — containerd CWE-345 - - 2026-07-01
CVE-2026-47262 containerd image-triggered runtime DoS via unbounded group parsing — containerd CWE-400 - - 2026-07-01
CVE-2026-46680 containerd user ID handling bypass allows runAsNonRoot evasion — containerd CWE-269 - - 2026-07-01
CVE-2026-53488 containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull — containerd CWE-20 - - 2026-07-01
CVE-2025-64329 containerd CRI server: Host memory exhaustion through Attach goroutine leak — containerd CWE-401 7.7 - 2025-11-07
CVE-2024-25621 containerd affected by a local privilege escalation via wide permissions on CRI directory — containerd CWE-279 7.3 High 2025-11-06
CVE-2025-47291 containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. — containerd CWE-266 7.7AI High AI 2025-05-21
CVE-2025-47290 Containerd vulnerable to host filesystem access during image unpack — containerd CWE-367 6.3AI Medium AI 2025-05-20
CVE-2024-40635 containerd has an integer overflow in User ID handling — containerd CWE-190 4.6 Medium 2025-03-17
CVE-2023-25173 containerd supplementary groups are not set up properly — containerd CWE-863 5.3 Medium 2023-02-16
CVE-2023-25153 containerd OCI image importer memory exhaustion — containerd CWE-770 6.2 Medium 2023-02-16
CVE-2022-23471 containerd CRI stream server: Host memory exhaustion through terminal resize goroutine leak — containerd CWE-400 5.7 Medium 2022-12-07
CVE-2022-31030 containerd CRI plugin: Host memory exhaustion through ExecSync — containerd CWE-400 5.5 Medium 2022-06-06
CVE-2022-24778 Incorrect Authorization in imgcrypt — imgcrypt CWE-863 7.5 High 2022-03-25
CVE-2022-23648 Insecure handling of image volumes in containerd CRI plugin — containerd CWE-200 7.5 High 2022-03-03
CVE-2021-43816 Improper Preservation of Permissions in containerd — containerd CWE-281 8.0 High 2022-01-05
CVE-2021-41103 Insufficiently restricted permissions on plugin directories — containerd CWE-22 7.8 - 2021-10-04
CVE-2021-32760 Archive package allows chmod of file outside of unpack target directory — containerd CWE-668 5.0 Medium 2021-07-19
CVE-2021-21334 environment variable leak — containerd CWE-668 6.3 Medium 2021-03-10
CVE-2020-15257 containerd-shim API Exposed to Host Network Containers — containerd CWE-669 5.2 Medium 2020-12-01
CVE-2020-15157 containerd can be coerced into leaking credentials during image pull — containerd CWE-522 6.1 Medium 2020-10-16

This page lists every published CVE security advisory associated with containerd. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.