VendorsKata Containerskata_containersall versions
Vulnerabilities

Kata Containers Kata Containers

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2026-24054
Kata Containers Runtime: Host block device can be hotplugged to the VM if the container image is malformed or contains no layers
Published 2026-01-29 · Analyzed
10.0EPSS 0.005
CVE-2026-44210
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
Published 2026-07-23 · Analyzed
9.9EPSS 0.006
CVE-2026-24834
Kata Container to Guest micro VM privilege escalation
Published 2026-02-19 · Modified
9.3EPSS 0.002
CVE-2020-27151
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
Published 2020-12-07 · Modified
9.0EPSS 0.020
CVE-2026-41326
Kata Containers: CopyFile Policy Subversion via Symlinks
Published 2026-04-24 · Modified
8.8EPSS 0.004