VendorsLinux Foundationcontainerdall versions
Vulnerabilities

Linux Foundation The Linux Foundation containerd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2026-50195
containerd: CRI checkpoint import allows local image tag poisoning
Published 2026-07-01 · Analyzed
9.9EPSS 0.003
CVE-2026-53492
containerd CRI checkpoint restore CDI annotation smuggling
Published 2026-07-01 · Analyzed
9.6EPSS 0.003
CVE-2026-53488
containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
Published 2026-07-01 · Analyzed
9.4EPSS 0.002
CVE-2021-43816
Improper Preservation of Permissions in containerd
Published 2022-01-05 · Modified
9.1EPSS 0.017
CVE-2026-53489
containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
Published 2026-07-01 · Analyzed
8.2EPSS 0.002
CVE-2023-25173
containerd supplementary groups are not set up properly
Published 2023-02-16 · Modified
7.8EPSS 0.005
CVE-2021-41103
Insufficiently restricted permissions on plugin directories
Published 2021-10-04 · Modified
7.8EPSS 0.005
CVE-2024-40635
containerd has an integer overflow in User ID handling
Published 2025-03-17 · Analyzed
7.8EPSS 0.003
CVE-2026-46680
containerd user ID handling bypass allows runAsNonRoot evasion
Published 2026-07-01 · Analyzed
7.8EPSS 0.002
CVE-2024-25621
containerd affected by a local privilege escalation via wide permissions on CRI directory
Published 2025-11-06 · Analyzed
7.8EPSS 0.002
CVE-2025-47290
Containerd vulnerable to host filesystem access during image unpack
Published 2025-05-20 · Analyzed
7.6EPSS 0.005
CVE-2022-23648
Insecure handling of image volumes in containerd CRI plugin
Published 2022-03-03 · Modified
7.5EPSS 0.274
CVE-2025-47291
containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.
Published 2025-05-21 · Analyzed
7.5EPSS 0.003
CVE-2025-64329
containerd CRI server: Host memory exhaustion through Attach goroutine leak
Published 2025-11-07 · Analyzed
6.9EPSS 0.002
CVE-2021-32760
Archive package allows chmod of file outside of unpack target directory
Published 2021-07-19 · Modified
6.8EPSS 0.016
CVE-2022-23471
containerd CRI stream server: Host memory exhaustion through terminal resize goroutine leak
Published 2022-12-07 · Modified
6.5EPSS 0.011
CVE-2021-21334
environment variable leak
Published 2021-03-10 · Modified
6.3EPSS 0.020
CVE-2023-25153
containerd OCI image importer memory exhaustion
Published 2023-02-16 · Modified
6.2EPSS 0.004
CVE-2020-15157
containerd can be coerced into leaking credentials during image pull
Published 2020-10-16 · Modified
6.1EPSS 0.023
CVE-2022-31030
containerd CRI plugin: Host memory exhaustion through ExecSync
Published 2022-06-06 · Modified
5.5EPSS 0.004
CVE-2026-47262
containerd image-triggered runtime DoS via unbounded group parsing
Published 2026-07-01 · Analyzed
5.5EPSS 0.003
CVE-2020-15257
containerd-shim API Exposed to Host Network Containers
Published 2020-12-01 · Modified
5.2EPSS 0.032