VendorsAmazonfirecrackerall versions
Vulnerabilities

Amazon Firecracker

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-18960
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.
Published 2019-12-11 · Modified
9.8EPSS 0.033
CVE-2026-5747
Out-of-bounds Write in Firecracker virtio-pci Transport
Published 2026-04-07 · Analyzed
8.7EPSS 0.002
CVE-2020-27174
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than intended on the host.
Published 2020-10-16 · Modified
7.5EPSS 0.017
CVE-2026-1386
Arbitrary Host File Overwrite via Symlink in Firecracker Jailer
Published 2026-01-23 · Analyzed
6.0EPSS 0.002
CVE-2020-16843
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network interface, and an availability problem for the microVM network interface on which the issue is triggered.
Published 2020-08-04 · Modified
5.9EPSS 0.017